{"grype_matches":[{"artifact":{"id":"792f91aafc41c5ea","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.26:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.26","type":"java-archive","version":"1.26","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"a78a8747147d2c5807683e76ec2b633e95c14fe9","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/snakeyaml-1.26.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mjmj-j48q-9wg2","versionConstraint":"<=1.33 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.26"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mjmj-j48q-9wg2","fix":{"state":"fixed","versions":["2.0"],"available":[{"date":"2023-03-05","kind":"first-observed","version":"2.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1471","cwe":"CWE-20","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-1471","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1471","date":"2026-10-08","epss":0.99569,"percentile":0.99946}],"risk":78.65951,"urls":["https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2","https://nvd.nist.gov/vuln/detail/CVE-2022-1471","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64581479","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64634374","https://bitbucket.org/snakeyaml/snakeyaml/wiki/CVE-2022-1471","https://github.com/mbechler/marshalsec","https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true","https://bitbucket.org/snakeyaml/snakeyaml/commits/5014df1a36f50aca54405bb8433bc99a8847f758","https://bitbucket.org/snakeyaml/snakeyaml/commits/acc44099f5f4af26ff86b4e4e4cc1c874e2dc5c4","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64876314","https://groups.google.com/g/kubernetes-security-announce/c/mwrakFaEdnc","http://packetstormsecurity.com/files/175095/PyTorch-Model-Server-Registration-Deserialization-Remote-Code-Execution.html","http://www.openwall.com/lists/oss-security/2023/11/19/1","https://security.netapp.com/advisory/ntap-20230818-0015","https://security.netapp.com/advisory/ntap-20240621-0006","https://snyk.io/blog/unsafe-deserialization-snakeyaml-java-cve-2022-1471","https://confluence.atlassian.com/security/cve-2022-1471-snakeyaml-library-rce-vulnerability-in-multiple-products-1296171009.html","https://infosecwriteups.com/%EF%B8%8F-inside-the-160-comment-fight-to-fix-snakeyamls-rce-default-1a20c5ca4d4c"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mjmj-j48q-9wg2","description":"SnakeYaml Constructor Deserialization Remote Code Execution"},"relatedVulnerabilities":[{"id":"CVE-2022-1471","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1471","cwe":"CWE-20","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-1471","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1471","date":"2026-10-08","epss":0.99569,"percentile":0.99946}],"urls":["http://packetstormsecurity.com/files/175095/PyTorch-Model-Server-Registration-Deserialization-Remote-Code-Execution.html","http://www.openwall.com/lists/oss-security/2023/11/19/1","https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64581479","https://confluence.atlassian.com/security/cve-2022-1471-snakeyaml-library-rce-vulnerability-in-multiple-products-1296171009.html","https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2","https://github.com/mbechler/marshalsec","https://groups.google.com/g/kubernetes-security-announce/c/mwrakFaEdnc","https://infosecwriteups.com/%EF%B8%8F-inside-the-160-comment-fight-to-fix-snakeyamls-rce-default-1a20c5ca4d4c","https://security.netapp.com/advisory/ntap-20230818-0015/","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1471","description":"SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond."}]},{"artifact":{"id":"d1631d475c37518a","cpes":["cpe:2.3:a:libgnutls30:libgnutls30:3.7.9-2\\+deb12u7:*:*:*:*:*:*:*"],"name":"libgnutls30","purl":"pkg:deb/debian/libgnutls30@3.7.9-2%2Bdeb12u7?arch=amd64&distro=debian-12.15&upstream=gnutls28","type":"deb","version":"3.7.9-2+deb12u7","language":"","licenses":["sha256:bb7e5c24b3e27bbba5671dd710d159a0066833bda4caa1d55d8027ffed539337"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libgnutls30/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libgnutls30:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-3389","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnutls28","version":"3.7.9-2+deb12u7"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2011-3389","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"risk":3.66635,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"urls":["http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/","http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx","http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx","http://curl.haxx.se/docs/adv_20120124B.html","http://downloads.asterisk.org/pub/security/AST-2016-001.html","http://ekoparty.org/2011/juliano-rizzo.php","http://eprint.iacr.org/2004/111","http://eprint.iacr.org/2006/136","http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html","http://isc.sans.edu/diary/SSL+TLS+part+3+/11635","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html","http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html","http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html","http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://marc.info/?l=bugtraq&m=132750579901589&w=2","http://marc.info/?l=bugtraq&m=132872385320240&w=2","http://marc.info/?l=bugtraq&m=133365109612558&w=2","http://marc.info/?l=bugtraq&m=133728004526190&w=2","http://marc.info/?l=bugtraq&m=134254866602253&w=2","http://marc.info/?l=bugtraq&m=134254957702612&w=2","http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue","http://osvdb.org/74829","http://rhn.redhat.com/errata/RHSA-2012-0508.html","http://rhn.redhat.com/errata/RHSA-2013-1455.html","http://secunia.com/advisories/45791","http://secunia.com/advisories/47998","http://secunia.com/advisories/48256","http://secunia.com/advisories/48692","http://secunia.com/advisories/48915","http://secunia.com/advisories/48948","http://secunia.com/advisories/49198","http://secunia.com/advisories/55322","http://secunia.com/advisories/55350","http://secunia.com/advisories/55351","http://security.gentoo.org/glsa/glsa-201203-02.xml","http://security.gentoo.org/glsa/glsa-201406-32.xml","http://support.apple.com/kb/HT4999","http://support.apple.com/kb/HT5001","http://support.apple.com/kb/HT5130","http://support.apple.com/kb/HT5281","http://support.apple.com/kb/HT5501","http://support.apple.com/kb/HT6150","http://technet.microsoft.com/security/advisory/2588513","http://vnhacker.blogspot.com/2011/09/beast.html","http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf","http://www.debian.org/security/2012/dsa-2398","http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html","http://www.ibm.com/developerworks/java/jdk/alerts/","http://www.imperialviolet.org/2011/09/23/chromeandbeast.html","http://www.insecure.cl/Beast-SSL.rar","http://www.kb.cert.org/vuls/id/864643","http://www.mandriva.com/security/advisories?name=MDVSA-2012:058","http://www.opera.com/docs/changelogs/mac/1151/","http://www.opera.com/docs/changelogs/mac/1160/","http://www.opera.com/docs/changelogs/unix/1151/","http://www.opera.com/docs/changelogs/unix/1160/","http://www.opera.com/docs/changelogs/windows/1151/","http://www.opera.com/docs/changelogs/windows/1160/","http://www.opera.com/support/kb/view/1004/","http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html","http://www.redhat.com/support/errata/RHSA-2011-1384.html","http://www.redhat.com/support/errata/RHSA-2012-0006.html","http://www.securityfocus.com/bid/49388","http://www.securityfocus.com/bid/49778","http://www.securitytracker.com/id/1029190","http://www.securitytracker.com/id?1025997","http://www.securitytracker.com/id?1026103","http://www.securitytracker.com/id?1026704","http://www.ubuntu.com/usn/USN-1263-1","http://www.us-cert.gov/cas/techalerts/TA12-010A.html","https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail","https://bugzilla.novell.com/show_bug.cgi?id=719047","https://bugzilla.redhat.com/show_bug.cgi?id=737506","https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006","https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862","https://hermes.opensuse.org/messages/13154861","https://hermes.opensuse.org/messages/13155432","https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."}]},{"artifact":{"id":"792f91aafc41c5ea","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.26:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.26","type":"java-archive","version":"1.26","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"a78a8747147d2c5807683e76ec2b633e95c14fe9","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/snakeyaml-1.26.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3mc7-4q67-w48m","versionConstraint":"<1.31 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.26"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3mc7-4q67-w48m","fix":{"state":"fixed","versions":["1.31"],"available":[{"date":"2022-09-12","kind":"first-observed","version":"1.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25857","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-25857","date":"2026-10-08","epss":0.02749,"percentile":0.85777}],"risk":2.06175,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-25857","https://github.com/snakeyaml/snakeyaml/commit/fc300780da21f4bb92c148bc90257201220cf174","https://bitbucket.org/snakeyaml/snakeyaml/commits/fc300780da21f4bb92c148bc90257201220cf174","https://bitbucket.org/snakeyaml/snakeyaml/issues/525","https://security.snyk.io/vuln/SNYK-JAVA-ORGYAML-2806360","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.netapp.com/advisory/ntap-20240315-0010"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3mc7-4q67-w48m","description":"Uncontrolled Resource Consumption in snakeyaml"},"relatedVulnerabilities":[{"id":"CVE-2022-25857","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-25857","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-25857","date":"2026-10-08","epss":0.02749,"percentile":0.85777}],"urls":["https://bitbucket.org/snakeyaml/snakeyaml/commits/fc300780da21f4bb92c148bc90257201220cf174","https://bitbucket.org/snakeyaml/snakeyaml/issues/525","https://github.com/snakeyaml/snakeyaml/commit/fc300780da21f4bb92c148bc90257201220cf174","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.netapp.com/advisory/ntap-20240315-0010/","https://security.snyk.io/vuln/SNYK-JAVA-ORGYAML-2806360"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-25857","description":"The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4341","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4341","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"risk":1.7445,"urls":["https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736712","description":"The net/url package does not set a limit on the number of query parameters in a query.\n\nWhile the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61726","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"urls":["https://go.dev/cl/736712","https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4341","https://access.redhat.com/errata/RHSA-2026:10096","https://access.redhat.com/errata/RHSA-2026:10104","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:11408","https://access.redhat.com/errata/RHSA-2026:11414","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12279","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13542","https://access.redhat.com/errata/RHSA-2026:13548","https://access.redhat.com/errata/RHSA-2026:13571","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:15984","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17446","https://access.redhat.com/errata/RHSA-2026:17460","https://access.redhat.com/errata/RHSA-2026:17463","https://access.redhat.com/errata/RHSA-2026:17468","https://access.redhat.com/errata/RHSA-2026:17595","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:18913","https://access.redhat.com/errata/RHSA-2026:19013","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26420","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:2681","https://access.redhat.com/errata/RHSA-2026:2706","https://access.redhat.com/errata/RHSA-2026:2708","https://access.redhat.com/errata/RHSA-2026:2709","https://access.redhat.com/errata/RHSA-2026:2754","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:2844","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:2914","https://access.redhat.com/errata/RHSA-2026:2920","https://access.redhat.com/errata/RHSA-2026:3035","https://access.redhat.com/errata/RHSA-2026:3040","https://access.redhat.com/errata/RHSA-2026:3089","https://access.redhat.com/errata/RHSA-2026:3092","https://access.redhat.com/errata/RHSA-2026:3184","https://access.redhat.com/errata/RHSA-2026:3186","https://access.redhat.com/errata/RHSA-2026:3187","https://access.redhat.com/errata/RHSA-2026:3188","https://access.redhat.com/errata/RHSA-2026:3192","https://access.redhat.com/errata/RHSA-2026:3193","https://access.redhat.com/errata/RHSA-2026:3291","https://access.redhat.com/errata/RHSA-2026:3296","https://access.redhat.com/errata/RHSA-2026:3297","https://access.redhat.com/errata/RHSA-2026:3298","https://access.redhat.com/errata/RHSA-2026:3336","https://access.redhat.com/errata/RHSA-2026:3337","https://access.redhat.com/errata/RHSA-2026:3340","https://access.redhat.com/errata/RHSA-2026:3341","https://access.redhat.com/errata/RHSA-2026:3343","https://access.redhat.com/errata/RHSA-2026:3391","https://access.redhat.com/errata/RHSA-2026:3416","https://access.redhat.com/errata/RHSA-2026:3427","https://access.redhat.com/errata/RHSA-2026:3459","https://access.redhat.com/errata/RHSA-2026:3468","https://access.redhat.com/errata/RHSA-2026:3469","https://access.redhat.com/errata/RHSA-2026:3470","https://access.redhat.com/errata/RHSA-2026:3471","https://access.redhat.com/errata/RHSA-2026:3472","https://access.redhat.com/errata/RHSA-2026:3473","https://access.redhat.com/errata/RHSA-2026:3489","https://access.redhat.com/errata/RHSA-2026:3506","https://access.redhat.com/errata/RHSA-2026:3556","https://access.redhat.com/errata/RHSA-2026:3559","https://access.redhat.com/errata/RHSA-2026:3668","https://access.redhat.com/errata/RHSA-2026:3669","https://access.redhat.com/errata/RHSA-2026:36873","https://access.redhat.com/errata/RHSA-2026:36882","https://access.redhat.com/errata/RHSA-2026:3699","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:3752","https://access.redhat.com/errata/RHSA-2026:3753","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3812","https://access.redhat.com/errata/RHSA-2026:3813","https://access.redhat.com/errata/RHSA-2026:3814","https://access.redhat.com/errata/RHSA-2026:3815","https://access.redhat.com/errata/RHSA-2026:3816","https://access.redhat.com/errata/RHSA-2026:3817","https://access.redhat.com/errata/RHSA-2026:3818","https://access.redhat.com/errata/RHSA-2026:3820","https://access.redhat.com/errata/RHSA-2026:3821","https://access.redhat.com/errata/RHSA-2026:3822","https://access.redhat.com/errata/RHSA-2026:3831","https://access.redhat.com/errata/RHSA-2026:3833","https://access.redhat.com/errata/RHSA-2026:3835","https://access.redhat.com/errata/RHSA-2026:3836","https://access.redhat.com/errata/RHSA-2026:3838","https://access.redhat.com/errata/RHSA-2026:3839","https://access.redhat.com/errata/RHSA-2026:3840","https://access.redhat.com/errata/RHSA-2026:3841","https://access.redhat.com/errata/RHSA-2026:3843","https://access.redhat.com/errata/RHSA-2026:3854","https://access.redhat.com/errata/RHSA-2026:3855","https://access.redhat.com/errata/RHSA-2026:3856","https://access.redhat.com/errata/RHSA-2026:3864","https://access.redhat.com/errata/RHSA-2026:3869","https://access.redhat.com/errata/RHSA-2026:3874","https://access.redhat.com/errata/RHSA-2026:3875","https://access.redhat.com/errata/RHSA-2026:3879","https://access.redhat.com/errata/RHSA-2026:3880","https://access.redhat.com/errata/RHSA-2026:3884","https://access.redhat.com/errata/RHSA-2026:3898","https://access.redhat.com/errata/RHSA-2026:3905","https://access.redhat.com/errata/RHSA-2026:3906","https://access.redhat.com/errata/RHSA-2026:3928","https://access.redhat.com/errata/RHSA-2026:3929","https://access.redhat.com/errata/RHSA-2026:3930","https://access.redhat.com/errata/RHSA-2026:3931","https://access.redhat.com/errata/RHSA-2026:3932","https://access.redhat.com/errata/RHSA-2026:3958","https://access.redhat.com/errata/RHSA-2026:3959","https://access.redhat.com/errata/RHSA-2026:3960","https://access.redhat.com/errata/RHSA-2026:3970","https://access.redhat.com/errata/RHSA-2026:3971","https://access.redhat.com/errata/RHSA-2026:3972","https://access.redhat.com/errata/RHSA-2026:3973","https://access.redhat.com/errata/RHSA-2026:3974","https://access.redhat.com/errata/RHSA-2026:3977","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:3985","https://access.redhat.com/errata/RHSA-2026:40924","https://access.redhat.com/errata/RHSA-2026:4164","https://access.redhat.com/errata/RHSA-2026:4166","https://access.redhat.com/errata/RHSA-2026:4170","https://access.redhat.com/errata/RHSA-2026:4174","https://access.redhat.com/errata/RHSA-2026:4177","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41941","https://access.redhat.com/errata/RHSA-2026:4211","https://access.redhat.com/errata/RHSA-2026:4220","https://access.redhat.com/errata/RHSA-2026:4256","https://access.redhat.com/errata/RHSA-2026:4264","https://access.redhat.com/errata/RHSA-2026:4267","https://access.redhat.com/errata/RHSA-2026:4270","https://access.redhat.com/errata/RHSA-2026:4276","https://access.redhat.com/errata/RHSA-2026:4434","https://access.redhat.com/errata/RHSA-2026:4435","https://access.redhat.com/errata/RHSA-2026:4460","https://access.redhat.com/errata/RHSA-2026:4466","https://access.redhat.com/errata/RHSA-2026:4467","https://access.redhat.com/errata/RHSA-2026:4498","https://access.redhat.com/errata/RHSA-2026:4500","https://access.redhat.com/errata/RHSA-2026:4510","https://access.redhat.com/errata/RHSA-2026:4511","https://access.redhat.com/errata/RHSA-2026:4672","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:4753","https://access.redhat.com/errata/RHSA-2026:4892","https://access.redhat.com/errata/RHSA-2026:4901","https://access.redhat.com/errata/RHSA-2026:4907","https://access.redhat.com/errata/RHSA-2026:4939","https://access.redhat.com/errata/RHSA-2026:4942","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:4952","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5022","https://access.redhat.com/errata/RHSA-2026:5030","https://access.redhat.com/errata/RHSA-2026:5031","https://access.redhat.com/errata/RHSA-2026:5076","https://access.redhat.com/errata/RHSA-2026:5077","https://access.redhat.com/errata/RHSA-2026:5078","https://access.redhat.com/errata/RHSA-2026:5079","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:5129","https://access.redhat.com/errata/RHSA-2026:5130","https://access.redhat.com/errata/RHSA-2026:5131","https://access.redhat.com/errata/RHSA-2026:5132","https://access.redhat.com/errata/RHSA-2026:5145","https://access.redhat.com/errata/RHSA-2026:5146","https://access.redhat.com/errata/RHSA-2026:5168","https://access.redhat.com/errata/RHSA-2026:5327","https://access.redhat.com/errata/RHSA-2026:5394","https://access.redhat.com/errata/RHSA-2026:5439","https://access.redhat.com/errata/RHSA-2026:5444","https://access.redhat.com/errata/RHSA-2026:5447","https://access.redhat.com/errata/RHSA-2026:5452","https://access.redhat.com/errata/RHSA-2026:5461","https://access.redhat.com/errata/RHSA-2026:5463","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5533","https://access.redhat.com/errata/RHSA-2026:5544","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:5636","https://access.redhat.com/errata/RHSA-2026:56366","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:5645","https://access.redhat.com/errata/RHSA-2026:5649","https://access.redhat.com/errata/RHSA-2026:5665","https://access.redhat.com/errata/RHSA-2026:57013","https://access.redhat.com/errata/RHSA-2026:5807","https://access.redhat.com/errata/RHSA-2026:5851","https://access.redhat.com/errata/RHSA-2026:5852","https://access.redhat.com/errata/RHSA-2026:5853","https://access.redhat.com/errata/RHSA-2026:5948","https://access.redhat.com/errata/RHSA-2026:5950","https://access.redhat.com/errata/RHSA-2026:5952","https://access.redhat.com/errata/RHSA-2026:5968","https://access.redhat.com/errata/RHSA-2026:6184","https://access.redhat.com/errata/RHSA-2026:6192","https://access.redhat.com/errata/RHSA-2026:6226","https://access.redhat.com/errata/RHSA-2026:6251","https://access.redhat.com/errata/RHSA-2026:6277","https://access.redhat.com/errata/RHSA-2026:6278","https://access.redhat.com/errata/RHSA-2026:6428","https://access.redhat.com/errata/RHSA-2026:6429","https://access.redhat.com/errata/RHSA-2026:6497","https://access.redhat.com/errata/RHSA-2026:6554","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:6567","https://access.redhat.com/errata/RHSA-2026:6568","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:7052","https://access.redhat.com/errata/RHSA-2026:7249","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7676","https://access.redhat.com/errata/RHSA-2026:7854","https://access.redhat.com/errata/RHSA-2026:7942","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8218","https://access.redhat.com/errata/RHSA-2026:8229","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8431","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9848","https://access.redhat.com/security/cve/CVE-2025-61726","https://bugzilla.redhat.com/show_bug.cgi?id=2434432","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61726","description":"The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."}]},{"artifact":{"id":"792f91aafc41c5ea","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.26:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.26","type":"java-archive","version":"1.26","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"a78a8747147d2c5807683e76ec2b633e95c14fe9","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/snakeyaml-1.26.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.32"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9w3m-gqgf-c4p9","versionConstraint":"<1.32 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.26"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9w3m-gqgf-c4p9","fix":{"state":"fixed","versions":["1.32"],"available":[{"date":"2022-09-15","kind":"first-observed","version":"1.32"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38752","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38752","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38752","date":"2026-10-08","epss":0.02526,"percentile":0.84409}],"risk":1.45245,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-38752","https://bitbucket.org/snakeyaml/snakeyaml/issues/531/stackoverflow-oss-fuzz-47081","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47081","https://security.gentoo.org/glsa/202305-28","https://security.netapp.com/advisory/ntap-20240315-0009"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9w3m-gqgf-c4p9","description":"snakeYAML before 1.32 vulnerable to Denial of Service due to Out-of-bounds Write"},"relatedVulnerabilities":[{"id":"CVE-2022-38752","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38752","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38752","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38752","date":"2026-10-08","epss":0.02526,"percentile":0.84409}],"urls":["https://bitbucket.org/snakeyaml/snakeyaml/issues/531/stackoverflow-oss-fuzz-47081","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47081","https://security.gentoo.org/glsa/202305-28","https://security.netapp.com/advisory/ntap-20240315-0009/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-38752","description":"Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow."}]},{"artifact":{"id":"792f91aafc41c5ea","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.26:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.26","type":"java-archive","version":"1.26","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"a78a8747147d2c5807683e76ec2b633e95c14fe9","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/snakeyaml-1.26.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c4r9-r8fh-9vj2","versionConstraint":"<1.31 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.26"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c4r9-r8fh-9vj2","fix":{"state":"fixed","versions":["1.31"],"available":[{"date":"2022-09-16","kind":"first-observed","version":"1.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38749","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38749","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38749","date":"2026-10-08","epss":0.02061,"percentile":0.80751}],"risk":1.1850749999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-38749","https://bitbucket.org/snakeyaml/snakeyaml/issues/525/got-stackoverflowerror-for-many-open","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47024","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.gentoo.org/glsa/202305-28","https://arxiv.org/pdf/2306.05534.pdf","https://security.netapp.com/advisory/ntap-20240315-0010"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c4r9-r8fh-9vj2","description":"snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write"},"relatedVulnerabilities":[{"id":"CVE-2022-38749","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38749","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38749","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38749","date":"2026-10-08","epss":0.02061,"percentile":0.80751}],"urls":["https://bitbucket.org/snakeyaml/snakeyaml/issues/525/got-stackoverflowerror-for-many-open","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47024","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.gentoo.org/glsa/202305-28","https://security.netapp.com/advisory/ntap-20240315-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-38749","description":"Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow."}]},{"artifact":{"id":"792f91aafc41c5ea","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.26:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.26","type":"java-archive","version":"1.26","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"a78a8747147d2c5807683e76ec2b633e95c14fe9","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/snakeyaml-1.26.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-98wm-3w3q-mw94","versionConstraint":"<1.31 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.26"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-98wm-3w3q-mw94","fix":{"state":"fixed","versions":["1.31"],"available":[{"date":"2022-09-18","kind":"first-observed","version":"1.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38751","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38751","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38751","date":"2026-10-08","epss":0.01905,"percentile":0.79103}],"risk":1.095375,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-38751","https://bitbucket.org/snakeyaml/snakeyaml/issues/530/stackoverflow-oss-fuzz-47039","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47039","https://bitbucket.org/snakeyaml/snakeyaml/src/master/src/test/java/org/yaml/snakeyaml/issues/issue530/Fuzzy47039Test.java","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.gentoo.org/glsa/202305-28","https://security.netapp.com/advisory/ntap-20240315-0010"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-98wm-3w3q-mw94","description":"snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write"},"relatedVulnerabilities":[{"id":"CVE-2022-38751","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38751","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38751","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38751","date":"2026-10-08","epss":0.01905,"percentile":0.79103}],"urls":["https://bitbucket.org/snakeyaml/snakeyaml/issues/530/stackoverflow-oss-fuzz-47039","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47039","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.gentoo.org/glsa/202305-28","https://security.netapp.com/advisory/ntap-20240315-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-38751","description":"Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"1b0588f8ba059bb4","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"46509399d28f57ca32c6bb4b0d4e10e8f062051e","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rmj7-2vxq-3g9f","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rmj7-2vxq-3g9f","fix":{"state":"fixed","versions":["2.21.4"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.21.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"risk":0.95628,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://nvd.nist.gov/vuln/detail/CVE-2026-54513","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rmj7-2vxq-3g9f","description":"jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)"},"relatedVulnerabilities":[{"id":"CVE-2026-54513","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"urls":["https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54513","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"792f91aafc41c5ea","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.26:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.26","type":"java-archive","version":"1.26","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"a78a8747147d2c5807683e76ec2b633e95c14fe9","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/snakeyaml-1.26.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.32"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w37g-rhq8-7m4j","versionConstraint":"<1.32 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.26"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-w37g-rhq8-7m4j","fix":{"state":"fixed","versions":["1.32"],"available":[{"date":"2022-12-16","kind":"first-observed","version":"1.32"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41854","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-41854","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41854","date":"2026-10-08","epss":0.01548,"percentile":0.74267}],"risk":0.8900999999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-41854","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50355","https://bitbucket.org/snakeyaml/snakeyaml/commits/e230a1758842beec93d28eddfde568c21774780a","https://bitbucket.org/snakeyaml/snakeyaml/issues/531","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3DDXEXXWAZGF5AVHIPGFPXIWL6TSMKJE","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7MKE4XWRXTH32757H7QJU4ACS67DYDCR","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSPAJ5Y45A4ZDION2KN5RDWLHK4XKY2J","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3DDXEXXWAZGF5AVHIPGFPXIWL6TSMKJE","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MKE4XWRXTH32757H7QJU4ACS67DYDCR","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSPAJ5Y45A4ZDION2KN5RDWLHK4XKY2J","https://security.netapp.com/advisory/ntap-20240315-0009","https://security.netapp.com/advisory/ntap-20240621-0006"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w37g-rhq8-7m4j","description":"Snakeyaml vulnerable to Stack overflow leading to denial of service"},"relatedVulnerabilities":[{"id":"CVE-2022-41854","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H","metrics":{"baseScore":5.8,"impactScore":4,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41854","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-41854","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41854","date":"2026-10-08","epss":0.01548,"percentile":0.74267}],"urls":["https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50355","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3DDXEXXWAZGF5AVHIPGFPXIWL6TSMKJE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7MKE4XWRXTH32757H7QJU4ACS67DYDCR/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSPAJ5Y45A4ZDION2KN5RDWLHK4XKY2J/","https://security.netapp.com/advisory/ntap-20240315-0009/","https://security.netapp.com/advisory/ntap-20240621-0006/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41854","description":"Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack."}]},{"artifact":{"id":"9e40126b989ece04","cpes":["cpe:2.3:a:libtasn1-6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1-6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1-6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1_6:4.19.0-2\\+deb12u1:*:*:*:*:*:*:*"],"name":"libtasn1-6","purl":"pkg:deb/debian/libtasn1-6@4.19.0-2%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"4.19.0-2+deb12u1","language":"","licenses":["sha256:572ad60ad184d8f52c6dc66d83a61a68f137db560b3452ce00588c9ecf128a65"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtasn1-6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libtasn1-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtasn1-6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libtasn1-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-13151","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libtasn1-6","version":"4.19.0-2+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-13151","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-13151","date":"2026-10-08","epss":0.01175,"percentile":0.66615}],"risk":0.8812500000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-13151","description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string."},"relatedVulnerabilities":[{"id":"CVE-2025-13151","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-13151","date":"2026-10-08","epss":0.01175,"percentile":0.66615}],"urls":["https://gitlab.com/gnutls/libtasn1","https://gitlab.com/gnutls/libtasn1/-/merge_requests/121","http://www.openwall.com/lists/oss-security/2026/01/08/5","https://www.kb.cert.org/vuls/id/271649"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13151","description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4337","versionConstraint":"<1.24.13||>=1.25.0-0,<1.25.7||>=1.26.0-rc.1,<1.26.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4337","fix":{"state":"fixed","versions":["1.24.13","1.25.7","1.26.0-rc.3"],"available":[{"date":"2026-02-04","kind":"release","version":"1.24.13"},{"date":"2026-02-04","kind":"release","version":"1.25.7"},{"date":"2026-02-04","kind":"release","version":"1.26.0-rc.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"risk":0.8692500000000001,"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."},"relatedVulnerabilities":[{"id":"CVE-2025-68121","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217","https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","https://pkg.go.dev/vuln/GO-2026-4337"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68121","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."}]},{"artifact":{"id":"1b0588f8ba059bb4","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"46509399d28f57ca32c6bb4b0d4e10e8f062051e","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3rv-43j4-c7qm","versionConstraint":">=2.19.0,<=2.21.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j3rv-43j4-c7qm","fix":{"state":"fixed","versions":["2.21.4"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.21.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"risk":0.7792200000000001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://nvd.nist.gov/vuln/detail/CVE-2026-54512"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3rv-43j4-c7qm","description":"jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation"},"relatedVulnerabilities":[{"id":"CVE-2026-54512","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"urls":["https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54512","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"792f91aafc41c5ea","cpes":["cpe:2.3:a:org.yaml.snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:snakeyaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:org.yaml:snakeyaml:1.26:*:*:*:*:*:*:*","cpe:2.3:a:yaml:snakeyaml:1.26:*:*:*:*:*:*:*"],"name":"snakeyaml","purl":"pkg:maven/org.yaml/snakeyaml@1.26","type":"java-archive","version":"1.26","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.yaml","virtualPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","manifestName":"","pomArtifactID":"snakeyaml","archiveDigests":[{"value":"a78a8747147d2c5807683e76ec2b633e95c14fe9","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/snakeyaml-1.26.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/snakeyaml-1.26.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hhhw-99gj-p3c3","versionConstraint":"<1.31 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.yaml:snakeyaml","version":"1.26"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hhhw-99gj-p3c3","fix":{"state":"fixed","versions":["1.31"],"available":[{"date":"2022-09-18","kind":"first-observed","version":"1.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38750","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38750","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38750","date":"2026-10-08","epss":0.01253,"percentile":0.68566}],"risk":0.657825,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-38750","https://bitbucket.org/snakeyaml/snakeyaml/issues/526/stackoverflow-oss-fuzz-47027","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47027","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.gentoo.org/glsa/202305-28","https://security.netapp.com/advisory/ntap-20240315-0010"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hhhw-99gj-p3c3","description":"snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds Write"},"relatedVulnerabilities":[{"id":"CVE-2022-38750","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-38750","cwe":"CWE-121","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2022-38750","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-38750","date":"2026-10-08","epss":0.01253,"percentile":0.68566}],"urls":["https://bitbucket.org/snakeyaml/snakeyaml/issues/526/stackoverflow-oss-fuzz-47027","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47027","https://lists.debian.org/debian-lts-announce/2022/10/msg00001.html","https://security.gentoo.org/glsa/202305-28","https://security.netapp.com/advisory/ntap-20240315-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-38750","description":"Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow."}]},{"artifact":{"id":"ebed48cf05f6f771","cpes":["cpe:2.3:a:logback-classic:logback-classic:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback-classic:logback_classic:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_classic:logback-classic:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_classic:logback_classic:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-classic:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_classic:1.2.9:*:*:*:*:*:*:*"],"name":"logback-classic","purl":"pkg:maven/ch.qos.logback/logback-classic@1.2.9","type":"java-archive","version":"1.2.9","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/opt/cassandra/lib/logback-classic-1.2.9.jar","manifestName":"","pomArtifactID":"logback-classic","archiveDigests":[{"value":"7d495522b08a9a66084bf417e70eedf95ef706bc","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/logback-classic-1.2.9.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/logback-classic-1.2.9.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.2.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vmq6-5m68-f53m","versionConstraint":"<1.2.13 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-classic","version":"1.2.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vmq6-5m68-f53m","fix":{"state":"fixed","versions":["1.2.13"],"available":[{"date":"2023-12-06","kind":"first-observed","version":"1.2.13"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6378","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6378","date":"2026-10-08","epss":0.009,"percentile":0.58407}],"risk":0.6569999999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-6378","https://logback.qos.ch/news.html#1.3.12","https://github.com/qos-ch/logback/commit/9c782b45be4abdafb7e17481e24e7354c2acd1eb","https://github.com/qos-ch/logback/commit/b8eac23a9de9e05fb6d51160b3f46acd91af9731","https://logback.qos.ch/manual/receivers.html","https://github.com/qos-ch/logback/issues/745#issuecomment-1836227158","https://github.com/qos-ch/logback/commit/bb095154be011267b64e37a1d401546e7cc2b7c3","https://logback.qos.ch/news.html#1.2.13","https://security.netapp.com/advisory/ntap-20241129-0012"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vmq6-5m68-f53m","description":"logback serialization vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2023-6378","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6378","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6378","date":"2026-10-08","epss":0.009,"percentile":0.58407}],"urls":["https://logback.qos.ch/news.html#1.3.12","https://security.netapp.com/advisory/ntap-20241129-0012/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6378","description":"A serialization vulnerability in logback receiver component part of \nlogback version 1.4.11 allows an attacker to mount a Denial-Of-Service \nattack by sending poisoned data."}]},{"artifact":{"id":"2e0f9dcbf1c8cb58","cpes":["cpe:2.3:a:logback-core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.2.9:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.2.9","type":"java-archive","version":"1.2.9","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"cdaca0cf922c5791a8efa0063ec714ca974affe3","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/logback-core-1.2.9.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.2.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vmq6-5m68-f53m","versionConstraint":"<1.2.13 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.2.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vmq6-5m68-f53m","fix":{"state":"fixed","versions":["1.2.13"],"available":[{"date":"2023-12-06","kind":"first-observed","version":"1.2.13"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6378","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6378","date":"2026-10-08","epss":0.009,"percentile":0.58407}],"risk":0.6569999999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-6378","https://logback.qos.ch/news.html#1.3.12","https://github.com/qos-ch/logback/commit/9c782b45be4abdafb7e17481e24e7354c2acd1eb","https://github.com/qos-ch/logback/commit/b8eac23a9de9e05fb6d51160b3f46acd91af9731","https://logback.qos.ch/manual/receivers.html","https://github.com/qos-ch/logback/issues/745#issuecomment-1836227158","https://github.com/qos-ch/logback/commit/bb095154be011267b64e37a1d401546e7cc2b7c3","https://logback.qos.ch/news.html#1.2.13","https://security.netapp.com/advisory/ntap-20241129-0012"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vmq6-5m68-f53m","description":"logback serialization vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2023-6378","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6378","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6378","date":"2026-10-08","epss":0.009,"percentile":0.58407}],"urls":["https://logback.qos.ch/news.html#1.3.12","https://security.netapp.com/advisory/ntap-20241129-0012/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6378","description":"A serialization vulnerability in logback receiver component part of \nlogback version 1.4.11 allows an attacker to mount a Denial-Of-Service \nattack by sending poisoned data."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4601","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4601","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"risk":0.6255000000000001,"urls":["https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/752180","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-25679","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"urls":["https://go.dev/cl/752180","https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4601","https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10125","https://access.redhat.com/errata/RHSA-2026:10133","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10158","https://access.redhat.com/errata/RHSA-2026:10169","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:10701","https://access.redhat.com/errata/RHSA-2026:10712","https://access.redhat.com/errata/RHSA-2026:10929","https://access.redhat.com/errata/RHSA-2026:11217","https://access.redhat.com/errata/RHSA-2026:11375","https://access.redhat.com/errata/RHSA-2026:11412","https://access.redhat.com/errata/RHSA-2026:11413","https://access.redhat.com/errata/RHSA-2026:11686","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:11800","https://access.redhat.com/errata/RHSA-2026:11856","https://access.redhat.com/errata/RHSA-2026:11916","https://access.redhat.com/errata/RHSA-2026:11996","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13642","https://access.redhat.com/errata/RHSA-2026:13643","https://access.redhat.com/errata/RHSA-2026:13671","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:19017","https://access.redhat.com/errata/RHSA-2026:19022","https://access.redhat.com/errata/RHSA-2026:19026","https://access.redhat.com/errata/RHSA-2026:19027","https://access.redhat.com/errata/RHSA-2026:19031","https://access.redhat.com/errata/RHSA-2026:19032","https://access.redhat.com/errata/RHSA-2026:19049","https://access.redhat.com/errata/RHSA-2026:19055","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19128","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19181","https://access.redhat.com/errata/RHSA-2026:19184","https://access.redhat.com/errata/RHSA-2026:19185","https://access.redhat.com/errata/RHSA-2026:19207","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19475","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:20088","https://access.redhat.com/errata/RHSA-2026:20581","https://access.redhat.com/errata/RHSA-2026:20582","https://access.redhat.com/errata/RHSA-2026:20584","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:21696","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22733","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24386","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:25043","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26445","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28893","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:52389","https://access.redhat.com/errata/RHSA-2026:52390","https://access.redhat.com/errata/RHSA-2026:52391","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:5941","https://access.redhat.com/errata/RHSA-2026:5942","https://access.redhat.com/errata/RHSA-2026:5943","https://access.redhat.com/errata/RHSA-2026:5944","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:6341","https://access.redhat.com/errata/RHSA-2026:6344","https://access.redhat.com/errata/RHSA-2026:6382","https://access.redhat.com/errata/RHSA-2026:6383","https://access.redhat.com/errata/RHSA-2026:6388","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:6720","https://access.redhat.com/errata/RHSA-2026:6802","https://access.redhat.com/errata/RHSA-2026:6949","https://access.redhat.com/errata/RHSA-2026:7005","https://access.redhat.com/errata/RHSA-2026:7009","https://access.redhat.com/errata/RHSA-2026:7011","https://access.redhat.com/errata/RHSA-2026:7259","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7315","https://access.redhat.com/errata/RHSA-2026:7328","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7665","https://access.redhat.com/errata/RHSA-2026:7669","https://access.redhat.com/errata/RHSA-2026:7674","https://access.redhat.com/errata/RHSA-2026:7833","https://access.redhat.com/errata/RHSA-2026:7834","https://access.redhat.com/errata/RHSA-2026:7876","https://access.redhat.com/errata/RHSA-2026:7877","https://access.redhat.com/errata/RHSA-2026:7878","https://access.redhat.com/errata/RHSA-2026:7879","https://access.redhat.com/errata/RHSA-2026:7883","https://access.redhat.com/errata/RHSA-2026:7992","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8314","https://access.redhat.com/errata/RHSA-2026:8322","https://access.redhat.com/errata/RHSA-2026:8324","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8434","https://access.redhat.com/errata/RHSA-2026:8456","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:8484","https://access.redhat.com/errata/RHSA-2026:8490","https://access.redhat.com/errata/RHSA-2026:8491","https://access.redhat.com/errata/RHSA-2026:8493","https://access.redhat.com/errata/RHSA-2026:8840","https://access.redhat.com/errata/RHSA-2026:8841","https://access.redhat.com/errata/RHSA-2026:8842","https://access.redhat.com/errata/RHSA-2026:8845","https://access.redhat.com/errata/RHSA-2026:8847","https://access.redhat.com/errata/RHSA-2026:8848","https://access.redhat.com/errata/RHSA-2026:8849","https://access.redhat.com/errata/RHSA-2026:8851","https://access.redhat.com/errata/RHSA-2026:8852","https://access.redhat.com/errata/RHSA-2026:8853","https://access.redhat.com/errata/RHSA-2026:8855","https://access.redhat.com/errata/RHSA-2026:8856","https://access.redhat.com/errata/RHSA-2026:8860","https://access.redhat.com/errata/RHSA-2026:8877","https://access.redhat.com/errata/RHSA-2026:8878","https://access.redhat.com/errata/RHSA-2026:8879","https://access.redhat.com/errata/RHSA-2026:8881","https://access.redhat.com/errata/RHSA-2026:8882","https://access.redhat.com/errata/RHSA-2026:8930","https://access.redhat.com/errata/RHSA-2026:8931","https://access.redhat.com/errata/RHSA-2026:8949","https://access.redhat.com/errata/RHSA-2026:9043","https://access.redhat.com/errata/RHSA-2026:9044","https://access.redhat.com/errata/RHSA-2026:9052","https://access.redhat.com/errata/RHSA-2026:9090","https://access.redhat.com/errata/RHSA-2026:9093","https://access.redhat.com/errata/RHSA-2026:9094","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/errata/RHSA-2026:9434","https://access.redhat.com/errata/RHSA-2026:9435","https://access.redhat.com/errata/RHSA-2026:9436","https://access.redhat.com/errata/RHSA-2026:9439","https://access.redhat.com/errata/RHSA-2026:9440","https://access.redhat.com/errata/RHSA-2026:9448","https://access.redhat.com/errata/RHSA-2026:9453","https://access.redhat.com/errata/RHSA-2026:9461","https://access.redhat.com/errata/RHSA-2026:9695","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/errata/RHSA-2026:9872","https://access.redhat.com/security/cve/CVE-2026-25679","https://bugzilla.redhat.com/show_bug.cgi?id=2445356","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25679","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4981","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4981","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"risk":0.60975,"urls":["https://go.dev/cl/767860","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78803","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."},"relatedVulnerabilities":[{"id":"CVE-2026-33811","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"urls":["https://go.dev/cl/767860","https://go.dev/issue/78803","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4981","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:35995","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36617","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36776","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:39266","https://access.redhat.com/errata/RHSA-2026:39272","https://access.redhat.com/errata/RHSA-2026:39319","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54556","https://access.redhat.com/errata/RHSA-2026:54584","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56790","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60302","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61313","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/security/cve/CVE-2026-33811","https://bugzilla.redhat.com/show_bug.cgi?id=2467822","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33811","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4977","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4977","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"risk":0.5984999999999999,"urls":["https://go.dev/cl/771520","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78987","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."},"relatedVulnerabilities":[{"id":"CVE-2026-42499","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"urls":["https://go.dev/cl/771520","https://go.dev/issue/78987","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4977","https://access.redhat.com/errata/RHSA-2026:17713","https://access.redhat.com/errata/RHSA-2026:17714","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:63163","https://access.redhat.com/errata/RHSA-2026:63332","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:64818","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67148","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-42499","https://bugzilla.redhat.com/show_bug.cgi?id=2467809","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42499","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4986","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4986","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"risk":0.588,"urls":["https://go.dev/cl/759940","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78566","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-39820","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"urls":["https://go.dev/cl/759940","https://go.dev/issue/78566","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4986","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54883","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57401","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-39820","https://bugzilla.redhat.com/show_bug.cgi?id=2467820","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39820","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4918","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4918","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"risk":0.58575,"urls":["https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/761581","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."},"relatedVulnerabilities":[{"id":"CVE-2026-33814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"urls":["https://go.dev/cl/761581","https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4918","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57367","https://access.redhat.com/errata/RHSA-2026:57408","https://access.redhat.com/errata/RHSA-2026:57545","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60441","https://access.redhat.com/errata/RHSA-2026:60442","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60447","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60478","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:60668","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62410","https://access.redhat.com/errata/RHSA-2026:62550","https://access.redhat.com/errata/RHSA-2026:62551","https://access.redhat.com/errata/RHSA-2026:63046","https://access.redhat.com/errata/RHSA-2026:63047","https://access.redhat.com/errata/RHSA-2026:63048","https://access.redhat.com/errata/RHSA-2026:63050","https://access.redhat.com/errata/RHSA-2026:63091","https://access.redhat.com/errata/RHSA-2026:63096","https://access.redhat.com/errata/RHSA-2026:63097","https://access.redhat.com/errata/RHSA-2026:63103","https://access.redhat.com/errata/RHSA-2026:63104","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:63637","https://access.redhat.com/errata/RHSA-2026:63639","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/security/cve/CVE-2026-33814","https://bugzilla.redhat.com/show_bug.cgi?id=2467815","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33814","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.561275,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.561275,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.561275,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.561275,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"2b3a2ba7a41a0529","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4-4:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"a6231fb14cfeaaac","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4-4:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"ec73073218fd031a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"c5b18ac268f2ccdf","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.54855,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4009","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4009","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61723","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61723","date":"2026-10-08","epss":0.00661,"percentile":0.50098}],"risk":0.49575,"urls":["https://go.dev/cl/709858","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75676","description":"The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input.\n\nThis affects programs which parse untrusted PEM inputs."},"relatedVulnerabilities":[{"id":"CVE-2025-61723","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61723","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61723","date":"2026-10-08","epss":0.00661,"percentile":0.50098}],"urls":["https://go.dev/cl/709858","https://go.dev/issue/75676","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4009","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61723","description":"The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4006","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4006","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61725","date":"2026-10-08","epss":0.00647,"percentile":0.49441}],"risk":0.48525,"urls":["https://go.dev/issue/75680","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709860","description":"The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61725","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61725","date":"2026-10-08","epss":0.00647,"percentile":0.49441}],"urls":["https://go.dev/cl/709860","https://go.dev/issue/75680","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4006","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61725","description":"The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9669","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"risk":0.47492499999999993,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."},"relatedVulnerabilities":[{"id":"CVE-2026-9669","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9669","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"risk":0.47492499999999993,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."},"relatedVulnerabilities":[{"id":"CVE-2026-9669","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9669","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"risk":0.47492499999999993,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."},"relatedVulnerabilities":[{"id":"CVE-2026-9669","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9669","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9669","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"risk":0.47492499999999993,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."},"relatedVulnerabilities":[{"id":"CVE-2026-9669","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9669","cwe":"CWE-121","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-9669","date":"2026-10-08","epss":0.00605,"percentile":0.47336}],"urls":["https://github.com/python/cpython/commit/157a5df8cb5d82b33f918a7489e72ce95ceb12b6","https://github.com/python/cpython/commit/1ba6135eae75ad8413413caeeedb56ae72320636","https://github.com/python/cpython/commit/5755d0f083949ff3c5bf3a37e673e24e306b036e","https://github.com/python/cpython/commit/619a12b2e545391dc436b3af79dda22337382a6f","https://github.com/python/cpython/commit/938ec030e90c5e53f1faac6fab1643f14e4f4a79","https://github.com/python/cpython/commit/991e6cf86496718c4ef00b362d640e00cb5c85b2","https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d","https://github.com/python/cpython/issues/150599","https://github.com/python/cpython/pull/150600","https://mail.python.org/archives/list/security-announce@python.org/thread/DBJZETMGUIFK7DVUWMOXHD3Z6IX2QPSX/","http://www.openwall.com/lists/oss-security/2026/06/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9669","description":"bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4870","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4870","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"risk":0.46575,"urls":["https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763767","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.\n\nThis only affects TLS 1.3."},"relatedVulnerabilities":[{"id":"CVE-2026-32283","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"urls":["https://go.dev/cl/763767","https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4870","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11704","https://access.redhat.com/errata/RHSA-2026:11711","https://access.redhat.com/errata/RHSA-2026:11712","https://access.redhat.com/errata/RHSA-2026:11863","https://access.redhat.com/errata/RHSA-2026:11881","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17075","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19134","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19136","https://access.redhat.com/errata/RHSA-2026:19137","https://access.redhat.com/errata/RHSA-2026:19139","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19156","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19351","https://access.redhat.com/errata/RHSA-2026:19352","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19369","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55898","https://access.redhat.com/errata/RHSA-2026:55900","https://access.redhat.com/errata/RHSA-2026:55901","https://access.redhat.com/errata/RHSA-2026:55902","https://access.redhat.com/errata/RHSA-2026:55903","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:57802","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65343","https://access.redhat.com/errata/RHSA-2026:65514","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66084","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:66523","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/security/cve/CVE-2026-32283","https://bugzilla.redhat.com/show_bug.cgi?id=2456338","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32283","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4971","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4971","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"risk":0.46499999999999997,"urls":["https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://go.dev/cl/775320"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79006","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."},"relatedVulnerabilities":[{"id":"CVE-2026-39836","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"urls":["https://go.dev/cl/775320","https://go.dev/issue/79006","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4971"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39836","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4947","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4947","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"risk":0.46125000000000005,"urls":["https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758320","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."},"relatedVulnerabilities":[{"id":"CVE-2026-32280","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"urls":["https://go.dev/cl/758320","https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4947","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16476","https://access.redhat.com/errata/RHSA-2026:16477","https://access.redhat.com/errata/RHSA-2026:16505","https://access.redhat.com/errata/RHSA-2026:16508","https://access.redhat.com/errata/RHSA-2026:16532","https://access.redhat.com/errata/RHSA-2026:16534","https://access.redhat.com/errata/RHSA-2026:16535","https://access.redhat.com/errata/RHSA-2026:16537","https://access.redhat.com/errata/RHSA-2026:16542","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21338","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:22130","https://access.redhat.com/errata/RHSA-2026:22141","https://access.redhat.com/errata/RHSA-2026:22258","https://access.redhat.com/errata/RHSA-2026:22260","https://access.redhat.com/errata/RHSA-2026:22268","https://access.redhat.com/errata/RHSA-2026:22309","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22415","https://access.redhat.com/errata/RHSA-2026:22422","https://access.redhat.com/errata/RHSA-2026:22465","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22840","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22958","https://access.redhat.com/errata/RHSA-2026:22959","https://access.redhat.com/errata/RHSA-2026:22960","https://access.redhat.com/errata/RHSA-2026:22961","https://access.redhat.com/errata/RHSA-2026:22962","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23244","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24359","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24478","https://access.redhat.com/errata/RHSA-2026:24716","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:28196","https://access.redhat.com/errata/RHSA-2026:28198","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:39894","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49526","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49838","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:59834","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61685","https://access.redhat.com/errata/RHSA-2026:61906","https://access.redhat.com/errata/RHSA-2026:61907","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/security/cve/CVE-2026-32280","https://bugzilla.redhat.com/show_bug.cgi?id=2456339","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32280","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"risk":0.45675000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8376","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"risk":0.45214,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."},"relatedVulnerabilities":[{"id":"CVE-2026-8376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5037","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5037","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"risk":0.4432500000000001,"urls":["https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/783621","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname.\n\nWith a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."},"relatedVulnerabilities":[{"id":"CVE-2026-27145","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"urls":["https://go.dev/cl/783621","https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5037","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:29980","https://access.redhat.com/errata/RHSA-2026:29981","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46394","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49705","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:49729","https://access.redhat.com/errata/RHSA-2026:49744","https://access.redhat.com/errata/RHSA-2026:49765","https://access.redhat.com/errata/RHSA-2026:49770","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:52946","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53416","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54427","https://access.redhat.com/errata/RHSA-2026:54432","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55899","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59556","https://access.redhat.com/errata/RHSA-2026:59557","https://access.redhat.com/errata/RHSA-2026:59558","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:59579","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60386","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60388","https://access.redhat.com/errata/RHSA-2026:60390","https://access.redhat.com/errata/RHSA-2026:60391","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:63016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68335","https://access.redhat.com/security/cve/CVE-2026-27145","https://bugzilla.redhat.com/show_bug.cgi?id=2484207","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27145","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69534","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"risk":0.44175000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."},"relatedVulnerabilities":[{"id":"CVE-2025-69534","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69534","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"risk":0.44175000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."},"relatedVulnerabilities":[{"id":"CVE-2025-69534","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69534","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"risk":0.44175000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."},"relatedVulnerabilities":[{"id":"CVE-2025-69534","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69534","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69534","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"risk":0.44175000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."},"relatedVulnerabilities":[{"id":"CVE-2025-69534","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-69534","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-69534","date":"2026-10-08","epss":0.00589,"percentile":0.46465}],"urls":["https://github.com/Python-Markdown/markdown","https://github.com/Python-Markdown/markdown/actions/runs/15736122892","https://github.com/Python-Markdown/markdown/issues/1534","http://www.openwall.com/lists/oss-security/2026/03/06/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19155","https://access.redhat.com/errata/RHSA-2026:19366","https://access.redhat.com/errata/RHSA-2026:20674","https://access.redhat.com/errata/RHSA-2026:20676","https://access.redhat.com/errata/RHSA-2026:20677","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/security/cve/CVE-2025-69534","https://bugzilla.redhat.com/show_bug.cgi?id=2444839","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534","description":"Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions."}]},{"artifact":{"id":"1b0588f8ba059bb4","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"46509399d28f57ca32c6bb4b0d4e10e8f062051e","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.19.0,<2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.21.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.21.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"85369d5a3515d91a","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u4","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.430965,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4342","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4342","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"risk":0.430675,"urls":["https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736713","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."},"relatedVulnerabilities":[{"id":"CVE-2025-61728","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"urls":["https://go.dev/cl/736713","https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4342","http://www.openwall.com/lists/oss-security/2026/01/15/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61728","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"aa527ab8cb576b14","cpes":["cpe:2.3:a:gzip:gzip:1.12-1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/debian/gzip@1.12-1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.12-1","language":"","licenses":["FSF-manpages","GFDL-1.3+-no-invariant","GFDL-3","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gzip.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41992","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gzip","version":"1.12-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41992","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-08","epss":0.00564,"percentile":0.4513}],"risk":0.42300000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41992","description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.  This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d."},"relatedVulnerabilities":[{"id":"CVE-2026-41992","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-08","epss":0.00564,"percentile":0.4513}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=e7378c2d421be6a286922374425680bbe9ad8b7d","https://www.gnu.org/software/gzip/","http://www.openwall.com/lists/oss-security/2026/08/23/1","http://www.openwall.com/lists/oss-security/2026/08/25/1","http://www.openwall.com/lists/oss-security/2026/08/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41992","description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5038","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5038","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"risk":0.42,"urls":["https://go.dev/cl/774481","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79217","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-42504","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"urls":["https://go.dev/cl/774481","https://go.dev/issue/79217","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5038"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42504","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."}]},{"artifact":{"id":"92a0932246c06383","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-core-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"50f3b4bd59b9ff51a0ed493e7b5abaf5c39709bf","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-core-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-core-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p6pp-m3f8-5c89","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p6pp-m3f8-5c89","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"risk":0.4095,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89","https://nvd.nist.gov/vuln/detail/CVE-2026-89407","https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/commit/731e794f62623aa0d86ced52490166be903fbb1d","https://github.com/FasterXML/jackson-core/commit/e7acd64cc99bd346704423dc2bfea1ab0a08ddff"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p6pp-m3f8-5c89","description":"jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()"},"relatedVulnerabilities":[{"id":"CVE-2026-89407","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89407","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89407","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89407","date":"2026-10-08","epss":0.00546,"percentile":0.44031}],"urls":["https://github.com/FasterXML/jackson-core/issues/1649","https://github.com/FasterXML/jackson-core/pull/1650","https://github.com/FasterXML/jackson-core/pull/1701","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-p6pp-m3f8-5c89"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89407","description":"NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates \"stringified numbers\" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers over the same character class -- an optional [0-9]* run, an optional dot, then a required [0-9]+ run -- so input that ultimately fails to match forces Java's backtracking engine to retry every possible split point of the digit run. \n\n\n\nMatching cost therefore grows with the square of the input length. \n\n\n\nAn attacker who can supply JSON that an application deserializes into a numeric target type reaches this method through jackson-databind's default String-to-number coercion (StdDeserializer and NumberDeserializers for BigDecimal, BigInteger, Double and Float). \n\n\n\nBecause StreamReadConstraints.maxStringLength defaults to 20,000,000 characters, no constraint bounds the input before it reaches the regex. \n\n\n\nTesting by the reporter confirmed O(n^2) growth across five consecutive input-size doublings, with a single 160,000-character string consuming roughly 74 seconds in one call; a small number of concurrent requests of ordinary body size can therefore exhaust a server's request-handling thread pool. \n\n\n\nThe affected method does not exist before 2.17.0, so 2.16.x and earlier releases are not affected. \n\n\n\nThe fix replaces both regular expressions with a hand-rolled single-pass scan."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.403975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.403975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.403975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.403975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.40370000000000006,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.40370000000000006,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.40370000000000006,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.40370000000000006,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"risk":0.39096000000000003,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42496","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"risk":0.38915,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path."},"relatedVulnerabilities":[{"id":"CVE-2026-42496","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"impactScore":6.1,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path."}]},{"artifact":{"id":"1b0588f8ba059bb4","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"46509399d28f57ca32c6bb4b0d4e10e8f062051e","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.19.0,<2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.21.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.21.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"risk":0.37867500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege."},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"92a0932246c06383","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-core-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"50f3b4bd59b9ff51a0ed493e7b5abaf5c39709bf","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-core-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-core-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r7wm-3cxj-wff9","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r7wm-3cxj-wff9","fix":{"state":"fixed","versions":["2.21.4"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.21.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"risk":0.3750299999999999,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://nvd.nist.gov/vuln/detail/CVE-2026-68494"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r7wm-3cxj-wff9","description":"jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)"},"relatedVulnerabilities":[{"id":"CVE-2026-68494","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"urls":["https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/advisories/GHSA-72hv-8253-57qq","https://www.cve.org/CVERecord?id=CVE-2026-18401"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68494","description":"The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08)."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8328","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"risk":0.37223500000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."},"relatedVulnerabilities":[{"id":"CVE-2026-8328","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8328","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"risk":0.37223500000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."},"relatedVulnerabilities":[{"id":"CVE-2026-8328","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8328","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"risk":0.37223500000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."},"relatedVulnerabilities":[{"id":"CVE-2026-8328","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8328","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8328","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"risk":0.37223500000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when  CVE-2021-4189 was fixed. While makepasv() was patched to replace  server-supplied PASV host addresses with the actual peer address  (getpeername()[0]), ftpcp() still calls parse227() directly and passes  the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."},"relatedVulnerabilities":[{"id":"CVE-2026-8328","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8328","cwe":"CWE-918","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-8328","date":"2026-10-08","epss":0.00683,"percentile":0.51056}],"urls":["https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381b5f","https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6ca06","https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a4f0","https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00763","https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fac1d","https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81bf9","https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0fceb","https://github.com/python/cpython/issues/87451","https://github.com/python/cpython/pull/149648","https://mail.python.org/archives/list/security-announce@python.org/thread/ITF2BAPBQEPYK3LDMPRSY435JGNHYNDP/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8328","description":"The ftpcp() function in Lib/ftplib.py was not updated when \nCVE-2021-4189 was fixed. While makepasv() was patched to replace \nserver-supplied PASV host addresses with the actual peer address \n(getpeername()[0]), ftpcp() still calls parse227() directly and passes \nthe raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"92a0932246c06383","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-core-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"50f3b4bd59b9ff51a0ed493e7b5abaf5c39709bf","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-core-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-core-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"risk":0.35325,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4155","versionConstraint":"<1.24.11||>=1.25.0,<1.25.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4155","fix":{"state":"fixed","versions":["1.24.11","1.25.5"],"available":[{"date":"2025-12-02","kind":"release","version":"1.24.11"},{"date":"2025-12-02","kind":"release","version":"1.25.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"risk":0.34275,"urls":["https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/725920","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"urls":["https://go.dev/cl/725920","https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4","https://pkg.go.dev/vuln/GO-2025-4155"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61729","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."}]},{"artifact":{"id":"2b3a2ba7a41a0529","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4-4:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"a6231fb14cfeaaac","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4-4:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"ec73073218fd031a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"c5b18ac268f2ccdf","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.33847,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"1b0588f8ba059bb4","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"46509399d28f57ca32c6bb4b0d4e10e8f062051e","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"1b0588f8ba059bb4","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"46509399d28f57ca32c6bb4b0d4e10e8f062051e","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.19.0,<=2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.21.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.21.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"risk":0.33558,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.32411999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.32411999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.32411999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.32411999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"fbd3380dfe250adc","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.22-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.22-1~deb12u1","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.22-1~deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4007","versionConstraint":"<1.24.9||>=1.25.0,<1.25.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4007","fix":{"state":"fixed","versions":["1.24.9","1.25.3"],"available":[{"date":"2025-10-13","kind":"release","version":"1.24.9"},{"date":"2025-10-13","kind":"release","version":"1.25.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58187","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58187","date":"2026-10-08","epss":0.00406,"percentile":0.32778}],"risk":0.3045,"urls":["https://go.dev/cl/709854","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75681","description":"Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate.\n\nThis affects programs which validate arbitrary certificate chains."},"relatedVulnerabilities":[{"id":"CVE-2025-58187","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58187","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58187","date":"2026-10-08","epss":0.00406,"percentile":0.32778}],"urls":["https://go.dev/cl/709854","https://go.dev/issue/75681","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4007","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58187","description":"Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.30067,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.30067,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.30067,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.30067,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"85369d5a3515d91a","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u4","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"risk":0.2985,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41080","description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document."},"relatedVulnerabilities":[{"id":"CVE-2026-41080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"urls":["https://blog.hartwork.org/posts/expat-2-8-0-released/","https://github.com/libexpat/libexpat/issues/47","https://github.com/libexpat/libexpat/pull/1183","https://www.openwall.com/lists/oss-security/2026/04/26/1","http://www.openwall.com/lists/oss-security/2026/04/26/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41080","description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document."}]},{"artifact":{"id":"4cab7ef7de016d31","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/debian/libpam-modules@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"372dffabd059479c","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/debian/libpam-modules-bin@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"ca1034d5d24bcf54","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/debian/libpam-runtime@1.5.2-6%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"87d8465053cf56c8","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/debian/libpam0g@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"21cf29d660e5e280","cpes":["cpe:2.3:a:com.google.guava:guava:27.0-jre:*:*:*:*:*:*:*","cpe:2.3:a:google:guava:27.0-jre:*:*:*:*:*:*:*","cpe:2.3:a:guava:guava:27.0-jre:*:*:*:*:*:*:*"],"name":"guava","purl":"pkg:maven/com.google.guava/guava@27.0-jre","type":"java-archive","version":"27.0-jre","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.google.guava","virtualPath":"/opt/cassandra/lib/guava-27.0-jre.jar","manifestName":"","pomArtifactID":"guava","archiveDigests":[{"value":"c6ad87d2575af8ac8ec38e28e75aefa882cc3a1f","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/guava-27.0-jre.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/guava-27.0-jre.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"32.0.0-android"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5mg8-w23w-74h3","versionConstraint":"<32.0.0-android (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.google.guava:guava","version":"27.0-jre"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5mg8-w23w-74h3","fix":{"state":"fixed","versions":["32.0.0-android"],"available":[{"date":"2023-11-10","kind":"first-observed","version":"32.0.0-android"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8908","cwe":"CWE-378","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2020-8908","cwe":"CWE-732","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8908","date":"2026-10-08","epss":0.00924,"percentile":0.59197}],"risk":0.29105999999999993,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2020-8908","https://github.com/google/guava/issues/4011","https://github.com/google/guava/commit/fec0dbc4634006a6162cfd4d0d09c962073ddf40","https://lists.apache.org/thread.html/r215b3d50f56faeb2f9383505f3e62faa9f549bb23e8a9848b78a968e@%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r4776f62dfae4a0006658542f43034a7fc199350e35a66d4e18164ee6@%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/r68d86f4b06c808204f62bcb254fcb5b0432528ee8d37a07ef4bc8222@%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba@%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/rb8c0f1b7589864396690fe42a91a71dea9412e86eec66dc85bbacaaf@%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/rbc7642b9800249553f13457e46b813bea1aec99d2bc9106510e00ff3@%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc2dbc4633a6eea1fcbce6831876cfa17b73759a98c65326d1896cb1a@%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rd5d58088812cf8e677d99b07f73c654014c524c94e7fedbdee047604@%3Ctorque-dev.db.apache.org%3E","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rfc27e2727a20a574f39273e0432aa97486a332f9b3068f6ac1346594@%3Cdev.myfaces.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95@%3Cgithub.arrow.apache.org%3E","https://lists.apache.org/thread.html/r037fed1d0ebde50c9caf8d99815db3093c344c3f651c5a49a09824ce@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r07ed3e4417ad043a27bee7bb33322e9bfc7d7e6d1719b8e3dfd95c14@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r161b87f8037bbaff400194a63cd2016c9a69f5949f06dcc79beeab54@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r2fe45d96eea8434b91592ca08109118f6308d60f6d0e21d52438cfb4@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r6874dfe26eefc41b7c9a5e4a0487846fc4accf8c78ff948b24a1104a@%3Cdev.drill.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r007add131977f4f576c232b25e024249a3d16f66aad14a4b52819d21@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r294be9d31c0312d2c0837087204b5d4bf49d0552890e6eec716fa6a6@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r3dd8881de891598d622227e9840dd7c2ef1d08abbb49e9690c7ae1bc@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r49549a8322f62cd3acfa4490d25bfba0be04f3f9ff4d14fe36199d27@%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r58a8775205ab1839dba43054b09a9ab3b25b423a4170b2413c4067ac@%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5b3d93dfdfb7708e796e8762ab40edbde8ff8add48aba53e5ea26f44@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r5d61b98ceb7bba939a651de5900dbd67be3817db6bfcc41c6e04e199@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r79e47ed555bdb1180e528420a7a2bb898541367a29a3bc6bbf0baf2c@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r7b0e81d8367264d6cad98766a469d64d11248eb654417809bfdacf09@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/ra7ab308481ee729f998691e8e3e02e93b1dedfc98f6b1cd3d86923b3@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb2364f4cf4d274eab5a7ecfaf64bf575cedf8b0173551997c749d322@%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rc607bc52f3507b8b9c28c6a747c3122f51ac24afe80af2a670785b97@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rcafc3a637d82bdc9a24036b2ddcad1e519dd0e6f848fcc3d606fd78f@%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/rd2704306ec729ccac726e50339b8a8f079515cc29ccb77713b16e7c5@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/re120f6b3d2f8222121080342c5801fdafca2f5188ceeb3b49c8a1d27@%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/reebbd63c25bc1a946caa419cec2be78079f8449d1af48e52d47c9e85@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf00b688ffa620c990597f829ff85fdbba8bf73ee7bfb34783e1f0d4e@%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rf9f0fa84b8ae1a285f0210bafec6de2a9eba083007d04640b82aa625@%3Cissues.geode.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://lists.apache.org/thread.html/rd7e12d56d49d73e2b8549694974b07561b79b05455f7f781954231bf@%3Cdev.pig.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.apache.org/thread.html/r007add131977f4f576c232b25e024249a3d16f66aad14a4b52819d21%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r07ed3e4417ad043a27bee7bb33322e9bfc7d7e6d1719b8e3dfd95c14%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r161b87f8037bbaff400194a63cd2016c9a69f5949f06dcc79beeab54%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r215b3d50f56faeb2f9383505f3e62faa9f549bb23e8a9848b78a968e%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r294be9d31c0312d2c0837087204b5d4bf49d0552890e6eec716fa6a6%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r2fe45d96eea8434b91592ca08109118f6308d60f6d0e21d52438cfb4%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r3dd8881de891598d622227e9840dd7c2ef1d08abbb49e9690c7ae1bc%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r4776f62dfae4a0006658542f43034a7fc199350e35a66d4e18164ee6%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/r49549a8322f62cd3acfa4490d25bfba0be04f3f9ff4d14fe36199d27%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r58a8775205ab1839dba43054b09a9ab3b25b423a4170b2413c4067ac%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5b3d93dfdfb7708e796e8762ab40edbde8ff8add48aba53e5ea26f44%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r5d61b98ceb7bba939a651de5900dbd67be3817db6bfcc41c6e04e199%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r6874dfe26eefc41b7c9a5e4a0487846fc4accf8c78ff948b24a1104a%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r68d86f4b06c808204f62bcb254fcb5b0432528ee8d37a07ef4bc8222%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r79e47ed555bdb1180e528420a7a2bb898541367a29a3bc6bbf0baf2c%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r7b0e81d8367264d6cad98766a469d64d11248eb654417809bfdacf09%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/ra7ab308481ee729f998691e8e3e02e93b1dedfc98f6b1cd3d86923b3%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb2364f4cf4d274eab5a7ecfaf64bf575cedf8b0173551997c749d322%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rb8c0f1b7589864396690fe42a91a71dea9412e86eec66dc85bbacaaf%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/rbc7642b9800249553f13457e46b813bea1aec99d2bc9106510e00ff3%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc2dbc4633a6eea1fcbce6831876cfa17b73759a98c65326d1896cb1a%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc607bc52f3507b8b9c28c6a747c3122f51ac24afe80af2a670785b97%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rcafc3a637d82bdc9a24036b2ddcad1e519dd0e6f848fcc3d606fd78f%40%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95%40%3Cgithub.arrow.apache.org%3E","https://lists.apache.org/thread.html/rd2704306ec729ccac726e50339b8a8f079515cc29ccb77713b16e7c5%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd5d58088812cf8e677d99b07f73c654014c524c94e7fedbdee047604%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rd7e12d56d49d73e2b8549694974b07561b79b05455f7f781954231bf%40%3Cdev.pig.apache.org%3E","https://lists.apache.org/thread.html/re120f6b3d2f8222121080342c5801fdafca2f5188ceeb3b49c8a1d27%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/reebbd63c25bc1a946caa419cec2be78079f8449d1af48e52d47c9e85%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf00b688ffa620c990597f829ff85fdbba8bf73ee7bfb34783e1f0d4e%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rf9f0fa84b8ae1a285f0210bafec6de2a9eba083007d04640b82aa625%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rfc27e2727a20a574f39273e0432aa97486a332f9b3068f6ac1346594%40%3Cdev.myfaces.apache.org%3E","https://github.com/google/guava/issues/4011#issuecomment-1578991974","https://github.com/google/guava/commit/feb83a1c8fd2e7670b244d5afd23cba5aca43284","https://security.netapp.com/advisory/ntap-20220210-0003"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5mg8-w23w-74h3","description":"Information Disclosure in Guava"},"relatedVulnerabilities":[{"id":"CVE-2020-8908","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-8908","cwe":"CWE-378","type":"Secondary","source":"cve-coordination@google.com"},{"cve":"CVE-2020-8908","cwe":"CWE-732","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-8908","date":"2026-10-08","epss":0.00924,"percentile":0.59197}],"urls":["https://github.com/google/guava/commit/fec0dbc4634006a6162cfd4d0d09c962073ddf40","https://github.com/google/guava/issues/4011","https://lists.apache.org/thread.html/r007add131977f4f576c232b25e024249a3d16f66aad14a4b52819d21%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r07ed3e4417ad043a27bee7bb33322e9bfc7d7e6d1719b8e3dfd95c14%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r161b87f8037bbaff400194a63cd2016c9a69f5949f06dcc79beeab54%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r215b3d50f56faeb2f9383505f3e62faa9f549bb23e8a9848b78a968e%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r294be9d31c0312d2c0837087204b5d4bf49d0552890e6eec716fa6a6%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r2fe45d96eea8434b91592ca08109118f6308d60f6d0e21d52438cfb4%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r3c3b33ee5bef0c67391d27a97cbfd89d44f328cf072b601b58d4e748%40%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r3dd8881de891598d622227e9840dd7c2ef1d08abbb49e9690c7ae1bc%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r4776f62dfae4a0006658542f43034a7fc199350e35a66d4e18164ee6%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/r49549a8322f62cd3acfa4490d25bfba0be04f3f9ff4d14fe36199d27%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r58a8775205ab1839dba43054b09a9ab3b25b423a4170b2413c4067ac%40%3Ccommon-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r5b3d93dfdfb7708e796e8762ab40edbde8ff8add48aba53e5ea26f44%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/r5d61b98ceb7bba939a651de5900dbd67be3817db6bfcc41c6e04e199%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r6874dfe26eefc41b7c9a5e4a0487846fc4accf8c78ff948b24a1104a%40%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/r68d86f4b06c808204f62bcb254fcb5b0432528ee8d37a07ef4bc8222%40%3Ccommits.ws.apache.org%3E","https://lists.apache.org/thread.html/r79e47ed555bdb1180e528420a7a2bb898541367a29a3bc6bbf0baf2c%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r7b0e81d8367264d6cad98766a469d64d11248eb654417809bfdacf09%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/r841c5e14e1b55281523ebcde661ece00b38a0569e00ef5e12bd5f6ba%40%3Cissues.maven.apache.org%3E","https://lists.apache.org/thread.html/ra7ab308481ee729f998691e8e3e02e93b1dedfc98f6b1cd3d86923b3%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rb2364f4cf4d274eab5a7ecfaf64bf575cedf8b0173551997c749d322%40%3Cgitbox.hive.apache.org%3E","https://lists.apache.org/thread.html/rb8c0f1b7589864396690fe42a91a71dea9412e86eec66dc85bbacaaf%40%3Ccommits.cxf.apache.org%3E","https://lists.apache.org/thread.html/rbc7642b9800249553f13457e46b813bea1aec99d2bc9106510e00ff3%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc2dbc4633a6eea1fcbce6831876cfa17b73759a98c65326d1896cb1a%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rc607bc52f3507b8b9c28c6a747c3122f51ac24afe80af2a670785b97%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rcafc3a637d82bdc9a24036b2ddcad1e519dd0e6f848fcc3d606fd78f%40%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/rd01f5ff0164c468ec7abc96ff7646cea3cce6378da2e4aa29c6bcb95%40%3Cgithub.arrow.apache.org%3E","https://lists.apache.org/thread.html/rd2704306ec729ccac726e50339b8a8f079515cc29ccb77713b16e7c5%40%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd5d58088812cf8e677d99b07f73c654014c524c94e7fedbdee047604%40%3Ctorque-dev.db.apache.org%3E","https://lists.apache.org/thread.html/rd7e12d56d49d73e2b8549694974b07561b79b05455f7f781954231bf%40%3Cdev.pig.apache.org%3E","https://lists.apache.org/thread.html/re120f6b3d2f8222121080342c5801fdafca2f5188ceeb3b49c8a1d27%40%3Cyarn-issues.hadoop.apache.org%3E","https://lists.apache.org/thread.html/reebbd63c25bc1a946caa419cec2be78079f8449d1af48e52d47c9e85%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rf00b688ffa620c990597f829ff85fdbba8bf73ee7bfb34783e1f0d4e%40%3Cyarn-dev.hadoop.apache.org%3E","https://lists.apache.org/thread.html/rf9f0fa84b8ae1a285f0210bafec6de2a9eba083007d04640b82aa625%40%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/rfc27e2727a20a574f39273e0432aa97486a332f9b3068f6ac1346594%40%3Cdev.myfaces.apache.org%3E","https://security.netapp.com/advisory/ntap-20220210-0003/","https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuoct2021.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-8908","description":"A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4012","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4012","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58186","date":"2026-10-08","epss":0.00565,"percentile":0.45157}],"risk":0.290975,"urls":["https://go.dev/cl/709855","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75672","description":"Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as \"a=;\", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-58186","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58186","date":"2026-10-08","epss":0.00565,"percentile":0.45157}],"urls":["https://go.dev/cl/709855","https://go.dev/issue/75672","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4012","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58186","description":"Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as \"a=;\", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4011","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4011","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58185","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58185","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"risk":0.28634,"urls":["https://go.dev/cl/709856","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75671","description":"Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2025-58185","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58185","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58185","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"urls":["https://go.dev/cl/709856","https://go.dev/issue/75671","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4011","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58185","description":"Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4015","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4015","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61724","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61724","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"risk":0.28634,"urls":["https://go.dev/issue/75716","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709859","description":"The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61724","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61724","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61724","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"urls":["https://go.dev/cl/709859","https://go.dev/issue/75716","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4015","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61724","description":"The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4013","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4013","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58188","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58188","date":"2026-10-08","epss":0.00381,"percentile":0.30022}],"risk":0.28575,"urls":["https://go.dev/issue/75675","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709853","description":"Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method.\n\nThis affects programs which validate arbitrary certificate chains."},"relatedVulnerabilities":[{"id":"CVE-2025-58188","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58188","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58188","date":"2026-10-08","epss":0.00381,"percentile":0.30022}],"urls":["https://go.dev/cl/709853","https://go.dev/issue/75675","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4013","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58188","description":"Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains."}]},{"artifact":{"id":"077923f667034501","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","type":"deb","version":"1:1.2.13.dfsg-1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"58c10ea7ffbc22a3","cpes":["cpe:2.3:a:gcc-12-base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12-base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"gcc-12-base","purl":"pkg:deb/debian/gcc-12-base@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/gcc-12-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"9454a77b5ea4561d","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"c2f4fec51904a8ce","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"1b0588f8ba059bb4","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"46509399d28f57ca32c6bb4b0d4e10e8f062051e","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.19.0,<2.21.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.21.6"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.21.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"815e91b90e5b4d9c","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/lz4-java-1.10.1.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xx22-p4ch-683r","versionConstraint":"<=1.11.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-xx22-p4ch-683r","fix":{"state":"fixed","versions":["1.11.1"],"available":[{"date":"2026-07-24","kind":"first-observed","version":"1.11.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"risk":0.26795,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r","https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xx22-p4ch-683r","description":"LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges"},"relatedVulnerabilities":[{"id":"CVE-2026-59949","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"urls":["https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1","https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59949","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4946","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4946","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"risk":0.26625,"urls":["https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758061","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service.\n\nThis only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."},"relatedVulnerabilities":[{"id":"CVE-2026-32281","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"urls":["https://go.dev/cl/758061","https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4946"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32281","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"2e0f9dcbf1c8cb58","cpes":["cpe:2.3:a:logback-core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.2.9:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.2.9","type":"java-archive","version":"1.2.9","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"cdaca0cf922c5791a8efa0063ec714ca974affe3","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/logback-core-1.2.9.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-pr98-23f8-jwxv","versionConstraint":"<1.3.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.2.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-pr98-23f8-jwxv","fix":{"state":"fixed","versions":["1.3.15"],"available":[{"date":"2025-01-04","kind":"first-observed","version":"1.3.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/RE:L/U:Clear","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12798","cwe":"CWE-917","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2024-12798","date":"2026-10-08","epss":0.00458,"percentile":0.37702}],"risk":0.24961000000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-12798","https://logback.qos.ch/news.html#1.5.13","https://github.com/qos-ch/logback/commit/2cb6d520df7592ef1c3a198f1b5df3c10c93e183","https://logback.qos.ch/news.html#1.3.15"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-pr98-23f8-jwxv","description":"QOS.CH logback-core Expression Language Injection vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-12798","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:L/U:Clear","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12798","cwe":"CWE-917","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2024-12798","date":"2026-10-08","epss":0.00458,"percentile":0.37702}],"urls":["https://logback.qos.ch/news.html#1.3.15","https://logback.qos.ch/news.html#1.5.13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-12798","description":"ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core\n      upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows\n      attacker to execute arbitrary code by compromising an existing\n      logback configuration file or by injecting an environment variable\n      before program execution.\n\n\n\n\n\nMalicious logback configuration files can allow the attacker to execute \narbitrary code using the JaninoEventEvaluator extension.\n\n\n\nA successful attack requires the user to have write access to a \nconfiguration file. Alternatively, the attacker could inject a malicious \nenvironment variable pointing to a malicious configuration file. In both \ncases, the attack requires existing privilege."}]},{"artifact":{"id":"1b0588f8ba059bb4","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"46509399d28f57ca32c6bb4b0d4e10e8f062051e","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3pjw-73gf-8qr5","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3pjw-73gf-8qr5","fix":{"state":"fixed","versions":["2.21.4"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.21.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"risk":0.243225,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5","https://nvd.nist.gov/vuln/detail/CVE-2026-59888","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3pjw-73gf-8qr5","description":"jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy"},"relatedVulnerabilities":[{"id":"CVE-2026-59888","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"urls":["https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59888","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"92a0932246c06383","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-core-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"50f3b4bd59b9ff51a0ed493e7b5abaf5c39709bf","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-core-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-core-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-72hv-8253-57qq","versionConstraint":">=2.19.0,<2.21.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-72hv-8253-57qq","fix":{"state":"fixed","versions":["2.21.1"],"available":[{"date":"2026-02-28","kind":"first-observed","version":"2.21.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"risk":0.24276000000000003,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://nvd.nist.gov/vuln/detail/CVE-2026-18401"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-72hv-8253-57qq","description":"jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition"},"relatedVulnerabilities":[{"id":"CVE-2026-18401","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"urls":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18401","description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4008","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4008","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58189","cwe":"CWE-532","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58189","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"risk":0.24101999999999998,"urls":["https://go.dev/issue/75652","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/707776","description":"When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped."},"relatedVulnerabilities":[{"id":"CVE-2025-58189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58189","cwe":"CWE-532","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58189","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"urls":["https://go.dev/cl/707776","https://go.dev/issue/75652","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4008","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58189","description":"When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4010","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4010","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-47912","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"risk":0.24101999999999998,"urls":["https://go.dev/cl/709857","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75678","description":"The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: \"http://[::1]/\". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement."},"relatedVulnerabilities":[{"id":"CVE-2025-47912","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-47912","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"urls":["https://go.dev/cl/709857","https://go.dev/issue/75678","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4010","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47912","description":"The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: \"http://[::1]/\". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11822","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11822","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"risk":0.2352,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."},"relatedVulnerabilities":[{"id":"CVE-2026-11822","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"1b0588f8ba059bb4","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"46509399d28f57ca32c6bb4b0d4e10e8f062051e","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5jmj-h7xm-6q6v","versionConstraint":">=2.19.0,<2.21.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5jmj-h7xm-6q6v","fix":{"state":"fixed","versions":["2.21.5"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.21.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"risk":0.228145,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://nvd.nist.gov/vuln/detail/CVE-2026-54515"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5jmj-h7xm-6q6v","description":"jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties"},"relatedVulnerabilities":[{"id":"CVE-2026-54515","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"urls":["https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54515","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4980","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4980","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"risk":0.21811499999999998,"urls":["https://go.dev/cl/771180","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78981","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."},"relatedVulnerabilities":[{"id":"CVE-2026-39826","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"urls":["https://go.dev/cl/771180","https://go.dev/issue/78981","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4980"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39826","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.21527,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-7458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-7458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7458","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7458","date":"2026-10-08","epss":0.00237,"percentile":0.13523}],"risk":0.21448500000000004,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7458","description":"An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause."},"relatedVulnerabilities":[{"id":"CVE-2025-7458","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7458","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7458","date":"2026-10-08","epss":0.00237,"percentile":0.13523}],"urls":["https://sqlite.org/forum/forumpost/16ce2bb7a639e29b","https://sqlite.org/src/info/12ad822d9b827777"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7458","description":"An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4976","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4976","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"risk":0.212695,"urls":["https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/770541","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions.\n\nWhen used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function.\n\nFor example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."},"relatedVulnerabilities":[{"id":"CVE-2026-39825","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"urls":["https://go.dev/cl/770541","https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4976"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39825","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5039","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5039","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"risk":0.21218,"urls":["https://go.dev/cl/777060","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79346","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."},"relatedVulnerabilities":[{"id":"CVE-2026-42507","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"urls":["https://go.dev/cl/777060","https://go.dev/issue/79346","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5039"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42507","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."}]},{"artifact":{"id":"f8ad3f5238dbcf6a","cpes":["cpe:2.3:a:tar:tar:1.34\\+dfsg-1.2\\+deb12u1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.34%2Bdfsg-1.2%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.34+dfsg-1.2+deb12u1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5704","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tar","version":"1.34+dfsg-1.2+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-5704","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"risk":0.210525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."},"relatedVulnerabilities":[{"id":"CVE-2026-5704","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"urls":["https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66514","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-5704","https://bugzilla.redhat.com/show_bug.cgi?id=2455360","http://www.openwall.com/lists/oss-security/2026/04/11/10","http://www.openwall.com/lists/oss-security/2026/04/11/11","http://www.openwall.com/lists/oss-security/2026/04/12/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-7709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-7709","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7709","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7709","date":"2026-10-08","epss":0.00353,"percentile":0.26886}],"risk":0.210035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-7709","description":"An integer overflow exists in the  FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds."},"relatedVulnerabilities":[{"id":"CVE-2025-7709","cvss":[{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7709","cwe":"CWE-190","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-7709","date":"2026-10-08","epss":0.00353,"percentile":0.26886}],"urls":["https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g","http://www.openwall.com/lists/oss-security/2025/09/06/2","http://www.openwall.com/lists/oss-security/2025/11/18/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7709","description":"An integer overflow exists in the  FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7010","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."},"relatedVulnerabilities":[{"id":"CVE-2026-7010","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4014","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4014","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58183","date":"2026-10-08","epss":0.00443,"percentile":0.36489}],"risk":0.20599499999999996,"urls":["https://go.dev/issue/75677","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709861","description":"tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations."},"relatedVulnerabilities":[{"id":"CVE-2025-58183","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58183","date":"2026-10-08","epss":0.00443,"percentile":0.36489}],"urls":["https://go.dev/cl/709861","https://go.dev/issue/75677","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4014","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58183","description":"tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.20110500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.20110500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.20110500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.20110500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"f8ad3f5238dbcf6a","cpes":["cpe:2.3:a:tar:tar:1.34\\+dfsg-1.2\\+deb12u1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.34%2Bdfsg-1.2%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.34+dfsg-1.2+deb12u1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2005-2541","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tar","version":"1.34+dfsg-1.2+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2005-2541","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"risk":0.1996,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."},"relatedVulnerabilities":[{"id":"CVE-2005-2541","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"urls":["http://marc.info/?l=bugtraq&m=112327628230258&w=2","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."}]},{"artifact":{"id":"fbd3380dfe250adc","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.22-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.22-1~deb12u1","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.22-1~deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.  Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.  CWE: CWE-1284: Improper Validation of Specified Quantity in Input  Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.  In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.  The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5856","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5856","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"risk":0.19673,"urls":["https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/775960","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."},"relatedVulnerabilities":[{"id":"CVE-2026-42505","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"urls":["https://go.dev/cl/775960","https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-5856"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42505","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4603","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4603","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"risk":0.19202999999999998,"urls":["https://go.dev/issue/77954","https://go.dev/cl/752081"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\".\n\nA new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."},"relatedVulnerabilities":[{"id":"CVE-2026-27142","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"urls":["https://go.dev/cl/752081","https://go.dev/issue/77954","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4603"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27142","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."}]},{"artifact":{"id":"815e91b90e5b4d9c","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/lz4-java-1.10.1.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4v53-57pg-c464","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-4v53-57pg-c464","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464","https://nvd.nist.gov/vuln/detail/CVE-2026-106452","https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4v53-57pg-c464","description":"yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header"},"relatedVulnerabilities":[{"id":"CVE-2026-106452","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106452","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106452","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/bb83dd16163cdb71231af06b0a5651881148a634","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106452","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"815e91b90e5b4d9c","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/lz4-java-1.10.1.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6cx8-rjf8-pr8g","versionConstraint":"<=1.11.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6cx8-rjf8-pr8g","fix":{"state":"fixed","versions":["1.11.2"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.11.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g","https://nvd.nist.gov/vuln/detail/CVE-2026-106453","https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6cx8-rjf8-pr8g","description":"yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryError"},"relatedVulnerabilities":[{"id":"CVE-2026-106453","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106453","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106453","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/6492ce5aca6bd03ff9e08ee18a2beb94c431371a","https://github.com/yawkat/lz4-java/releases/tag/v1.11.2","https://github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106453","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, LZ4DecompressorWithLength uses getDecompressedLength to trust the four-byte decompressed-length header before validating the compressed input, allowing a five-byte attacker-supplied input whose header declares a large output size to request up to approximately 2 GiB and exhaust the JVM heap. Convenience overloads backed by LZ4FastDecompressor or LZ4SafeDecompressor allocate the untrusted size, while overloads that write to a caller-provided destination buffer are not affected because the caller controls the destination size. This issue is fixed in version 1.11.2."}]},{"artifact":{"id":"815e91b90e5b4d9c","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/lz4-java-1.10.1.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gm45-99xc-r7wv","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gm45-99xc-r7wv","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"risk":0.191065,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv","https://nvd.nist.gov/vuln/detail/CVE-2026-106450","https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gm45-99xc-r7wv","description":"yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputs"},"relatedVulnerabilities":[{"id":"CVE-2026-106450","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106450","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106450","date":"2026-10-08","epss":0.00371,"percentile":0.28981}],"urls":["https://github.com/yawkat/lz4-java/commit/2acc0ec1ead226145c62a817c18c8ed49233a283","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-gm45-99xc-r7wv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106450","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4FrameInputStream readHeader() allocates two new 4 MiB block buffers whenever a maximum-block-size frame header is read, and the default concatenated-frame mode allows attacker-controlled streams containing many minimal empty frames to trigger roughly 8 MiB of allocation for every 11 input bytes. The stream produces no decompressed output while consuming CPU and garbage-collection time, so decompressed-size limits do not mitigate the issue; readSingleFrame mode is not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"85369d5a3515d91a","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u4","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"risk":0.18966000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"1b0588f8ba059bb4","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"46509399d28f57ca32c6bb4b0d4e10e8f062051e","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hgj6-7826-r7m5","versionConstraint":">=2.19.0,<2.21.4 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hgj6-7826-r7m5","fix":{"state":"fixed","versions":["2.21.4"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.21.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54514","date":"2026-10-08","epss":0.00368,"percentile":0.2857}],"risk":0.18952000000000002,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://nvd.nist.gov/vuln/detail/CVE-2026-54514"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hgj6-7826-r7m5","description":"jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)"},"relatedVulnerabilities":[{"id":"CVE-2026-54514","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54514","date":"2026-10-08","epss":0.00368,"percentile":0.2857}],"urls":["https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54514","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4865","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4865","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763762","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied.\n\nThese issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."},"relatedVulnerabilities":[{"id":"CVE-2026-32289","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/763762","https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4865"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32289","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4982","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4982","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/cl/769920","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78913","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-39823","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/769920","https://go.dev/issue/78913","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4982"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39823","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."}]},{"artifact":{"id":"58c10ea7ffbc22a3","cpes":["cpe:2.3:a:gcc-12-base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12-base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"gcc-12-base","purl":"pkg:deb/debian/gcc-12-base@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/gcc-12-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"9454a77b5ea4561d","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"c2f4fec51904a8ce","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-7017","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"risk":0.18031,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-7017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4970","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4970","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"risk":0.17748,"urls":["https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://go.dev/cl/797880"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79005","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /.\n\nFor example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."},"relatedVulnerabilities":[{"id":"CVE-2026-39822","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"urls":["https://go.dev/cl/797880","https://go.dev/issue/79005","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-4970"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39822","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6091","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6091","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"risk":0.17204999999999998,"urls":["https://go.dev/cl/807100","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80435","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-56858","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"urls":["https://go.dev/cl/807100","https://go.dev/issue/80435","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56858","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4340","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4340","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61730","date":"2026-10-08","epss":0.00329,"percentile":0.23929}],"risk":0.169435,"urls":["https://go.dev/issue/76443","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/724120","description":"During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."},"relatedVulnerabilities":[{"id":"CVE-2025-61730","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61730","date":"2026-10-08","epss":0.00329,"percentile":0.23929}],"urls":["https://go.dev/cl/724120","https://go.dev/issue/76443","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4340"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61730","description":"During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.167745,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4864","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4864","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"risk":0.16644,"urls":["https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763761","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root.\n\nThe Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."},"relatedVulnerabilities":[{"id":"CVE-2026-32282","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"urls":["https://go.dev/cl/763761","https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4864"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32282","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4175","versionConstraint":"<1.24.11||>=1.25.0,<1.25.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4175","fix":{"state":"fixed","versions":["1.24.11","1.25.5"],"available":[{"date":"2025-12-02","kind":"release","version":"1.24.11"},{"date":"2025-12-02","kind":"release","version":"1.25.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61727","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61727","date":"2026-10-08","epss":0.00284,"percentile":0.1914}],"risk":0.1633,"urls":["https://go.dev/issue/76442","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/723900","description":"An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com."},"relatedVulnerabilities":[{"id":"CVE-2025-61727","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61727","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61727","date":"2026-10-08","epss":0.00284,"percentile":0.1914}],"urls":["https://go.dev/cl/723900","https://go.dev/issue/76442","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4","https://pkg.go.dev/vuln/GO-2025-4175"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61727","description":"An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"1b0588f8ba059bb4","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.19.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.19.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.2","type":"java-archive","version":"2.19.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"46509399d28f57ca32c6bb4b0d4e10e8f062051e","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/jackson-databind-2.19.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.21.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vvgp-rfg2-7rr6","versionConstraint":">=2.19.0,<2.21.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.19.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vvgp-rfg2-7rr6","fix":{"state":"fixed","versions":["2.21.5"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.21.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"risk":0.161195,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6","https://nvd.nist.gov/vuln/detail/CVE-2026-77310","https://github.com/FasterXML/jackson-databind/pull/6058","https://github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.9","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.1","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vvgp-rfg2-7rr6","description":"jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization"},"relatedVulnerabilities":[{"id":"CVE-2026-77310","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77310","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of FromStringDeserializer.Std._deserialize() calls InetAddress.getByName() on attacker-controlled input, causing eager DNS resolution during deserialization and enabling DNS-based server-side request forgery and internal-host enumeration. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"d5e0daed57b0ef5c","cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.13%2Bdfsg1-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-1+deb12u2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"shadow","version":"1:4.13+dfsg1-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.14057999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"1853000d374a22b0","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/debian/passwd@1%3A4.13%2Bdfsg1-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-1+deb12u2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"shadow","version":"1:4.13+dfsg1-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.14057999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11824","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11824","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11824","date":"2026-10-08","epss":0.00175,"percentile":0.06432}],"risk":0.14,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11824","description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5."},"relatedVulnerabilities":[{"id":"CVE-2026-11824","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11824","date":"2026-10-08","epss":0.00175,"percentile":0.06432}],"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-heap-buffer-overflow-via-fts5-fts5chunkiterate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11824","description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5."}]},{"artifact":{"id":"fbd3380dfe250adc","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.22-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.22-1~deb12u1","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.22-1~deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.  Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake.  This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.  The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"492f98c2e7916f57","cpes":["cpe:2.3:a:libxtables12:libxtables12:1.8.9-2:*:*:*:*:*:*:*"],"name":"libxtables12","purl":"pkg:deb/debian/libxtables12@1.8.9-2?arch=amd64&distro=debian-12.15&upstream=iptables","type":"deb","version":"1.8.9-2","language":"","licenses":["Artistic","GPL-2","GPL-2+","custom"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxtables12/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libxtables12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxtables12:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libxtables12:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"iptables"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2012-2663","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"iptables","version":"1.8.9-2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2012-2663","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2012-2663","date":"2026-10-08","epss":0.02737,"percentile":0.85694}],"risk":0.13685,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-2663","description":"extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets.  NOTE: the CVE-2012-6638 fix makes this issue less relevant."},"relatedVulnerabilities":[{"id":"CVE-2012-2663","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2012-2663","date":"2026-10-08","epss":0.02737,"percentile":0.85694}],"urls":["http://www.spinics.net/lists/netfilter-devel/msg21248.html","https://bugzilla.redhat.com/show_bug.cgi?id=826702"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-2663","description":"extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets.  NOTE: the CVE-2012-6638 fix makes this issue less relevant."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.13413,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.13413,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.13413,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.13413,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"21cf29d660e5e280","cpes":["cpe:2.3:a:com.google.guava:guava:27.0-jre:*:*:*:*:*:*:*","cpe:2.3:a:google:guava:27.0-jre:*:*:*:*:*:*:*","cpe:2.3:a:guava:guava:27.0-jre:*:*:*:*:*:*:*"],"name":"guava","purl":"pkg:maven/com.google.guava/guava@27.0-jre","type":"java-archive","version":"27.0-jre","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.google.guava","virtualPath":"/opt/cassandra/lib/guava-27.0-jre.jar","manifestName":"","pomArtifactID":"guava","archiveDigests":[{"value":"c6ad87d2575af8ac8ec38e28e75aefa882cc3a1f","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/guava-27.0-jre.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/guava-27.0-jre.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"32.0.0-android"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7g45-4rm6-3mm3","versionConstraint":">=1.0,<32.0.0-android (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.google.guava:guava","version":"27.0-jre"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7g45-4rm6-3mm3","fix":{"state":"fixed","versions":["32.0.0-android"],"available":[{"date":"2023-11-10","kind":"first-observed","version":"32.0.0-android"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2976","cwe":"CWE-552","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2976","cwe":"CWE-552","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2976","date":"2026-10-08","epss":0.00248,"percentile":0.14727}],"risk":0.1302,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-2976","https://github.com/google/guava/issues/2575","https://github.com/google/guava/issues/6532","https://github.com/google/guava/commit/feb83a1c8fd2e7670b244d5afd23cba5aca43284","https://github.com/google/guava/releases/tag/v32.0.0","https://security.netapp.com/advisory/ntap-20230818-0008","https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.html","https://security.netapp.com/advisory/ntap-20241108-0002"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7g45-4rm6-3mm3","description":"Guava vulnerable to insecure use of temporary directory"},"relatedVulnerabilities":[{"id":"CVE-2023-2976","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2976","cwe":"CWE-552","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2976","cwe":"CWE-552","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2976","date":"2026-10-08","epss":0.00248,"percentile":0.14727}],"urls":["https://github.com/google/guava/issues/2575","https://security.netapp.com/advisory/ntap-20230818-0008/","https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01006.html","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2976","description":"Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.\n\nEven though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows."}]},{"artifact":{"id":"4cab7ef7de016d31","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/debian/libpam-modules@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.128525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"372dffabd059479c","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/debian/libpam-modules-bin@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.128525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"ca1034d5d24bcf54","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/debian/libpam-runtime@1.5.2-6%2Bdeb12u2?arch=all&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.128525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"87d8465053cf56c8","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.2-6\\+deb12u2:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/debian/libpam0g@1.5.2-6%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=pam","type":"deb","version":"1.5.2-6+deb12u2","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"pam","version":"1.5.2-6+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.128525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"eca37691b87c0860","cpes":["cpe:2.3:a:coreutils:coreutils:9.1-1:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.15","type":"deb","version":"9.1-1","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.list"},{"path":"/var/lib/dpkg/info/coreutils.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.postinst"},{"path":"/var/lib/dpkg/info/coreutils.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.postrm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"coreutils","version":"9.1-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.1284,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[{"id":"CVE-2016-2781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.12375000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.12375000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.12375000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.12375000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"2e0f9dcbf1c8cb58","cpes":["cpe:2.3:a:logback-core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.2.9:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.2.9","type":"java-archive","version":"1.2.9","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"cdaca0cf922c5791a8efa0063ec714ca974affe3","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/logback-core-1.2.9.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.33"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p47f-322f-whfh","versionConstraint":"<=1.5.32 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.2.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p47f-322f-whfh","fix":{"state":"fixed","versions":["1.5.33"],"available":[{"date":"2026-07-02","kind":"first-observed","version":"1.5.33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:L/U:Green","metrics":{"baseScore":1.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9828","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-9828","date":"2026-10-08","epss":0.00545,"percentile":0.43985}],"risk":0.11445,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-9828","https://logback.qos.ch/news.html#1.5.33"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p47f-322f-whfh","description":"QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2026-9828","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:L/U:Green","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9828","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-9828","date":"2026-10-08","epss":0.00545,"percentile":0.43985}],"urls":["https://logback.qos.ch/news.html#1.5.33"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9828","description":"Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.\n\nMore precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate objects from\n classes in the java.lang and java.util packages that are not explicitly\n blocked.\n\nAlthough deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.\n\n\n\nThis issue affects logback: through 1.5.32 inclusive."}]},{"artifact":{"id":"fbd3380dfe250adc","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.22-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.22-1~deb12u1","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.22-1~deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.   Impact summary: The NULL pointer dereference happens on a read which  leads to a crash and a Denial of Service for the affected client application.  CWE: CWE-476: NULL-pointer dereference  Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.  A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.  The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.  FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"815e91b90e5b4d9c","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/lz4-java-1.10.1.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-343h-94h5-c4wr","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-343h-94h5-c4wr","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"risk":0.11356499999999997,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr","https://nvd.nist.gov/vuln/detail/CVE-2026-106449","https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-343h-94h5-c4wr","description":"yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowError"},"relatedVulnerabilities":[{"id":"CVE-2026-106449","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106449","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106449","date":"2026-10-08","epss":0.00339,"percentile":0.25225}],"urls":["https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106449","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"0027543880aaec84","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/debian/libp11-kit0@0.24.1-2?arch=amd64&distro=debian-12.15&upstream=p11-kit","type":"deb","version":"0.24.1-2","language":"","licenses":["Apache-2.0","BSD-3-Clause","ISC","ISC+IBM","LGPL-2.1","LGPL-2.1+","permissive-like-automake-output","same-as-rest-of-p11kit"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13757","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"p11-kit","version":"0.24.1-2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13757","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-08","epss":0.00202,"percentile":0.09262}],"risk":0.11312000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."},"relatedVulnerabilities":[{"id":"CVE-2026-13757","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-08","epss":0.00202,"percentile":0.09262}],"urls":["https://access.redhat.com/errata/RHSA-2026:37469","https://access.redhat.com/errata/RHSA-2026:38342","https://access.redhat.com/errata/RHSA-2026:49667","https://access.redhat.com/errata/RHSA-2026:49668","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54387","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2026-13757","https://bugzilla.redhat.com/show_bug.cgi?id=2494556","https://github.com/advisories/GHSA-p2wm-69qx-x25w"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."}]},{"artifact":{"id":"d047530090108251","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.1-3:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/debian/libacl1@2.3.1-3?arch=amd64&distro=debian-12.15&upstream=acl","type":"deb","version":"2.3.1-3","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"acl","version":"2.3.1-3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.11168999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"2e0f9dcbf1c8cb58","cpes":["cpe:2.3:a:logback-core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.2.9:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.2.9","type":"java-archive","version":"1.2.9","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"cdaca0cf922c5791a8efa0063ec714ca974affe3","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/logback-core-1.2.9.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.34"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jhq6-gfmj-v8fx","versionConstraint":"<1.5.34 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.2.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jhq6-gfmj-v8fx","fix":{"state":"fixed","versions":["1.5.34"],"available":[{"date":"2026-07-16","kind":"first-observed","version":"1.5.34"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:M/U:Green","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10532","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-10532","date":"2026-10-08","epss":0.0037,"percentile":0.28843}],"risk":0.10915,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-10532","https://logback.qos.ch/news.html#1.5.34","https://github.com/qos-ch/logback/releases/tag/v_1.5.34"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jhq6-gfmj-v8fx","description":"Logback vulnerable to Object Injection through HardenedObjectInputStream modules"},"relatedVulnerabilities":[{"id":"CVE-2026-10532","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10532","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-10532","date":"2026-10-08","epss":0.0037,"percentile":0.28843}],"urls":["https://logback.qos.ch/news.html#1.5.34"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10532","description":"Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.\n\nMore precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.\n\n\nAlthough deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.\n\n\n\nThis issue affects logback: through 1.5.33 inclusive."}]},{"artifact":{"id":"85369d5a3515d91a","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u4","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"risk":0.106575,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"2e0f9dcbf1c8cb58","cpes":["cpe:2.3:a:logback-core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.2.9:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.2.9","type":"java-archive","version":"1.2.9","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"cdaca0cf922c5791a8efa0063ec714ca974affe3","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/logback-core-1.2.9.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.3.16"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-25qh-j22f-pwp8","versionConstraint":"<1.3.16 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.2.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-25qh-j22f-pwp8","fix":{"state":"fixed","versions":["1.3.16"],"available":[{"date":"2025-11-01","kind":"first-observed","version":"1.3.16"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11226","cwe":"CWE-20","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2025-11226","date":"2026-10-08","epss":0.00194,"percentile":0.08266}],"risk":0.10573000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-11226","https://logback.qos.ch/news.html#1.5.19","https://github.com/qos-ch/logback/commit/61f6a2544f36b3016e0efd434ee21f19269f1df7","https://github.com/qos-ch/logback/releases/tag/v_1.5.19","https://github.com/qos-ch/logback/issues/974","https://logback.qos.ch/news.html#1.3.16"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-25qh-j22f-pwp8","description":"QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing"},"relatedVulnerabilities":[{"id":"CVE-2025-11226","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:X/V:X/RE:M/U:Green","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11226","cwe":"CWE-20","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2025-11226","date":"2026-10-08","epss":0.00194,"percentile":0.08266}],"urls":["https://logback.qos.ch/news.html#1.3.16","https://logback.qos.ch/news.html#1.5.19"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11226","description":"ACE vulnerability in conditional configuration file processing  by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution.\n\n\n\nA successful attack requires the presence of Janino library and Spring Framework to be present on the user's class path. In addition, the attacker must  have write access to a \nconfiguration file. Alternatively, the attacker could inject a malicious \nenvironment variable pointing to a malicious configuration file. In both \ncases, the attack requires existing privilege."}]},{"artifact":{"id":"9db16cb04ae3b83d","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"fb1c9cf5b43a5af0","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"52548f50c4ff26c7","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"309b5ab55a11c7d0","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"722285f8005c2384","cpes":["cpe:2.3:a:libattr1:libattr1:1\\:2.5.1-4:*:*:*:*:*:*:*"],"name":"libattr1","purl":"pkg:deb/debian/libattr1@1%3A2.5.1-4?arch=amd64&distro=debian-12.15&upstream=attr","type":"deb","version":"1:2.5.1-4","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libattr1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libattr1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libattr1:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libattr1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"attr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"attr","version":"1:2.5.1-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54371","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-08","epss":0.00179,"percentile":0.06854}],"risk":0.10113499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54371","description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path."},"relatedVulnerabilities":[{"id":"CVE-2026-54371","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-08","epss":0.00179,"percentile":0.06854}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f","https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b","https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr","https://access.redhat.com/errata/RHSA-2026:34889","https://access.redhat.com/errata/RHSA-2026:56133","https://access.redhat.com/errata/RHSA-2026:59380","https://access.redhat.com/errata/RHSA-2026:60226","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/security/cve/CVE-2026-54371","https://bugzilla.redhat.com/show_bug.cgi?id=2490283","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54371","description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path."}]},{"artifact":{"id":"077923f667034501","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.2.13.dfsg-1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&upstream=zlib","type":"deb","version":"1:1.2.13.dfsg-1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"zlib","version":"1:1.2.13.dfsg-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-27171","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"risk":0.10027499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."},"relatedVulnerabilities":[{"id":"CVE-2026-27171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.0981,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.0981,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.0981,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.0981,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"2b3a2ba7a41a0529","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4-4:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"a6231fb14cfeaaac","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4-4:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"ec73073218fd031a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.4-4?arch=all&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"c5b18ac268f2ccdf","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4-4:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4-4:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.4-4?arch=amd64&distro=debian-12.15&upstream=ncurses","type":"deb","version":"6.4-4","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"ncurses","version":"6.4-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4869","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4869","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"risk":0.09555000000000001,"urls":["https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763766","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."},"relatedVulnerabilities":[{"id":"CVE-2026-32288","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"urls":["https://go.dev/cl/763766","https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4869"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32288","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."}]},{"artifact":{"id":"bab4532a87a829c8","cpes":["cpe:2.3:a:gpgv:gpgv:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/debian/gpgv@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.092635,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.09225,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.09225,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.09225,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.09225,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"751ec9ae4280dd32","cpes":["cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2-1.0:libbz2_1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2-1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2_1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2-1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2_1.0:1.0.8-5\\+b1:*:*:*:*:*:*:*"],"name":"libbz2-1.0","purl":"pkg:deb/debian/libbz2-1.0@1.0.8-5%2Bb1?arch=amd64&distro=debian-12.15&upstream=bzip2%401.0.8-5","type":"deb","version":"1.0.8-5+b1","language":"","licenses":["BSD-variant","GPL-2"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbz2-1.0/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libbz2-1.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bzip2","version":"1.0.8-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"bzip2","version":"1.0.8-5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-42250","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"risk":0.08918,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).  This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"},"relatedVulnerabilities":[{"id":"CVE-2026-42250","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"}]},{"artifact":{"id":"df01c68aff59530a","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.10.1-3\\+deb12u1:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/debian/libgcrypt20@1.10.1-3%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.10.1-3+deb12u1","language":"","licenses":["sha256:95db2f9da663f2bfe2aabe9c72fce9d6c9ae767b912f397d7823f50bd55a1a7d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libgcrypt20","version":"1.10.1-3+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2018-6829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6829","date":"2026-10-08","epss":0.01777,"percentile":0.77546}],"risk":0.08885000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6829","description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation."},"relatedVulnerabilities":[{"id":"CVE-2018-6829","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6829","date":"2026-10-08","epss":0.01777,"percentile":0.77546}],"urls":["https://github.com/weikengchen/attack-on-libgcrypt-elgamal","https://github.com/weikengchen/attack-on-libgcrypt-elgamal/wiki","https://lists.gnupg.org/pipermail/gcrypt-devel/2018-February/004394.html","https://www.oracle.com/security-alerts/cpujan2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6829","description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation."}]},{"artifact":{"id":"fbd3380dfe250adc","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.22-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.22-1~deb12u1","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.22-1~deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.  Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.  The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.  Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.  The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.  FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31486","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-31486","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31486","date":"2026-10-08","epss":0.01742,"percentile":0.7706}],"risk":0.08710000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31486","description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates."},"relatedVulnerabilities":[{"id":"CVE-2023-31486","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31486","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31486","date":"2026-10-08","epss":0.01742,"percentile":0.7706}],"urls":["http://www.openwall.com/lists/oss-security/2023/04/29/1","http://www.openwall.com/lists/oss-security/2023/05/03/3","http://www.openwall.com/lists/oss-security/2023/05/03/5","http://www.openwall.com/lists/oss-security/2023/05/07/2","https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/","https://github.com/chansen/p5-http-tiny/pull/153","https://hackeriet.github.io/cpan-http-tiny-overview/","https://www.openwall.com/lists/oss-security/2023/04/18/14","https://www.openwall.com/lists/oss-security/2023/05/03/4","https://www.reddit.com/r/perl/comments/111tadi/psa_httptiny_disabled_ssl_verification_by_default/","https://security.netapp.com/advisory/ntap-20241129-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31486","description":"HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"0027543880aaec84","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.24.1-2:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.24.1-2:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/debian/libp11-kit0@0.24.1-2?arch=amd64&distro=debian-12.15&upstream=p11-kit","type":"deb","version":"0.24.1-2","language":"","licenses":["Apache-2.0","BSD-3-Clause","ISC","ISC+IBM","LGPL-2.1","LGPL-2.1+","permissive-like-automake-output","same-as-rest-of-p11kit"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18938","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"p11-kit","version":"0.24.1-2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18938","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18938","date":"2026-10-08","epss":0.00152,"percentile":0.03827}],"risk":0.08512000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18938","description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems."},"relatedVulnerabilities":[{"id":"CVE-2026-18938","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18938","date":"2026-10-08","epss":0.00152,"percentile":0.03827}],"urls":["https://access.redhat.com/security/cve/CVE-2026-18938","https://bugzilla.redhat.com/show_bug.cgi?id=2478995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18938","description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-50812","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-50812","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50812","date":"2026-10-08","epss":0.0016,"percentile":0.04607}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50812","description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer."},"relatedVulnerabilities":[{"id":"CVE-2026-50812","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50812","date":"2026-10-08","epss":0.0016,"percentile":0.04607}],"urls":["https://gist.github.com/junius-sec/bb556f333957c5226dede314db0e9e91","https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d","https://sqlite.org/src/info/e807d4e3798efd53"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50812","description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer."}]},{"artifact":{"id":"fa8be228d5b7724c","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"55089f35a6363c37","cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-50813","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-50813","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50813","cwe":"CWE-126","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50813","date":"2026-10-08","epss":0.00159,"percentile":0.04405}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50813","description":"An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path"},"relatedVulnerabilities":[{"id":"CVE-2026-50813","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50813","cwe":"CWE-126","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50813","date":"2026-10-08","epss":0.00159,"percentile":0.04405}],"urls":["https://gist.github.com/junius-sec/f8acb66bafb80134c8e1a1c8c7c9f4f4","https://github.com/sqlite/sqlite/commit/c597ed79d1bd03f57198d10d1f431adda293cf2e","https://sqlite.org/src/info/869a51ae84df"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50813","description":"An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path"}]},{"artifact":{"id":"d047530090108251","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.1-3:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/debian/libacl1@2.3.1-3?arch=amd64&distro=debian-12.15&upstream=acl","type":"deb","version":"2.3.1-3","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"acl","version":"2.3.1-3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-54370","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"risk":0.081585,"urls":[],"severity":"High","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-54370","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."}]},{"artifact":{"id":"fbd3380dfe250adc","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.22-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.22-1~deb12u1","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.22-1~deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.  Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.  Applications performing SM2 signature generation are affected on all platforms.  FIPS Impact: no SM2 is not a FIPS algorithm."},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-45346","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2021-45346","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-45346","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-45346","date":"2026-10-08","epss":0.01614,"percentile":0.75265}],"risk":0.08070000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-45346","description":"A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect."},"relatedVulnerabilities":[{"id":"CVE-2021-45346","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-45346","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-45346","date":"2026-10-08","epss":0.01614,"percentile":0.75265}],"urls":["https://github.com/guyinatuxedo/sqlite3_record_leaking","https://security.netapp.com/advisory/ntap-20220303-0001/","https://sqlite.org/forum/forumpost/056d557c2f8c452ed5","https://sqlite.org/forum/forumpost/53de8864ba114bf6","https://www.sqlite.org/cves.html#status_of_recent_sqlite_cves"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-45346","description":"A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect."}]},{"artifact":{"id":"5ac1d1a0947c5131","cpes":["cpe:2.3:a:libproc2-0:libproc2-0:2\\:4.0.2-3:*:*:*:*:*:*:*","cpe:2.3:a:libproc2-0:libproc2_0:2\\:4.0.2-3:*:*:*:*:*:*:*","cpe:2.3:a:libproc2_0:libproc2-0:2\\:4.0.2-3:*:*:*:*:*:*:*","cpe:2.3:a:libproc2_0:libproc2_0:2\\:4.0.2-3:*:*:*:*:*:*:*","cpe:2.3:a:libproc2:libproc2-0:2\\:4.0.2-3:*:*:*:*:*:*:*","cpe:2.3:a:libproc2:libproc2_0:2\\:4.0.2-3:*:*:*:*:*:*:*"],"name":"libproc2-0","purl":"pkg:deb/debian/libproc2-0@2%3A4.0.2-3?arch=amd64&distro=debian-12.15&upstream=procps","type":"deb","version":"2:4.0.2-3","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libproc2-0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libproc2-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libproc2-0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libproc2-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"procps"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-4016","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"procps","version":"2:4.0.2-3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-4016","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4016","cwe":"CWE-122","type":"Secondary","source":"trellixpsirt@trellix.com"},{"cve":"CVE-2023-4016","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4016","date":"2026-10-08","epss":0.00256,"percentile":0.15808}],"risk":0.08064,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-4016","description":"Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap."},"relatedVulnerabilities":[{"id":"CVE-2023-4016","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"trellixpsirt@trellix.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4016","cwe":"CWE-122","type":"Secondary","source":"trellixpsirt@trellix.com"},{"cve":"CVE-2023-4016","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4016","date":"2026-10-08","epss":0.00256,"percentile":0.15808}],"urls":["https://gitlab.com/procps-ng/procps","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SUETRRT24OFGPYK6ACPM5VUGHNKH5CQ5/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4016","description":"Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap."}]},{"artifact":{"id":"145b97448d7e9318","cpes":["cpe:2.3:a:procps:procps:2\\:4.0.2-3:*:*:*:*:*:*:*"],"name":"procps","purl":"pkg:deb/debian/procps@2%3A4.0.2-3?arch=amd64&distro=debian-12.15","type":"deb","version":"2:4.0.2-3","language":"","licenses":["GPL-2","GPL-2.0+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/procps/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/procps/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/procps.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/procps.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/procps.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/procps.list"},{"path":"/var/lib/dpkg/info/procps.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/procps.postinst"},{"path":"/var/lib/dpkg/info/procps.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/procps.postrm"},{"path":"/var/lib/dpkg/info/procps.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/procps.preinst"},{"path":"/var/lib/dpkg/info/procps.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/procps.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-4016","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"procps","version":"2:4.0.2-3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-4016","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4016","cwe":"CWE-122","type":"Secondary","source":"trellixpsirt@trellix.com"},{"cve":"CVE-2023-4016","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4016","date":"2026-10-08","epss":0.00256,"percentile":0.15808}],"risk":0.08064,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-4016","description":"Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap."},"relatedVulnerabilities":[{"id":"CVE-2023-4016","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"trellixpsirt@trellix.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4016","cwe":"CWE-122","type":"Secondary","source":"trellixpsirt@trellix.com"},{"cve":"CVE-2023-4016","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4016","date":"2026-10-08","epss":0.00256,"percentile":0.15808}],"urls":["https://gitlab.com/procps-ng/procps","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SUETRRT24OFGPYK6ACPM5VUGHNKH5CQ5/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4016","description":"Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.    This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.    This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.07005999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.  Exploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.07005999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.  Exploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"aa527ab8cb576b14","cpes":["cpe:2.3:a:gzip:gzip:1.12-1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/debian/gzip@1.12-1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.12-1","language":"","licenses":["FSF-manpages","GFDL-1.3+-no-invariant","GFDL-3","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gzip.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41991","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gzip","version":"1.12-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-41991","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41991","cwe":"CWE-377","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41991","date":"2026-10-08","epss":0.00142,"percentile":0.02987}],"risk":0.06887,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41991","description":"GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.  This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269"},"relatedVulnerabilities":[{"id":"CVE-2026-41991","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41991","cwe":"CWE-377","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41991","date":"2026-10-08","epss":0.00142,"percentile":0.02987}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269","https://www.gnu.org/software/gzip/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41991","description":"GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.\n\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269"}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.36.0-7+deb12u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"< 5.36.0-7+deb12u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-15649","fix":{"state":"fixed","versions":["5.36.0-7+deb12u4"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.36.0-7+deb12u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"risk":0.066675,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."},"relatedVulnerabilities":[{"id":"CVE-2025-15649","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."}]},{"artifact":{"id":"f8ad3f5238dbcf6a","cpes":["cpe:2.3:a:tar:tar:1.34\\+dfsg-1.2\\+deb12u1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.34%2Bdfsg-1.2%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.34+dfsg-1.2+deb12u1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tar","version":"1.34+dfsg-1.2+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18508","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"risk":0.06627,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."},"relatedVulnerabilities":[{"id":"CVE-2026-18508","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.06615000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value."},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.06615000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value."},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.06615000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value."},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.06615000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value."},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"815e91b90e5b4d9c","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.10.1:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.10.1:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/at.yawk.lz4/lz4-java@1.10.1","type":"java-archive","version":"1.10.1","language":"java","licenses":["Apache License, Version 2.0"],"metadata":{"pomGroupID":"at.yawk.lz4","virtualPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"f541d7f910fe3d76f38f799c507c48cc81b12ecb","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/lz4-java-1.10.1.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/lz4-java-1.10.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mcr4-qmvw-px4g","versionConstraint":"<=1.11.3 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"at.yawk.lz4:lz4-java","version":"1.10.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mcr4-qmvw-px4g","fix":{"state":"fixed","versions":["1.11.4"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"1.11.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"risk":0.061419999999999995,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g","https://nvd.nist.gov/vuln/detail/CVE-2026-106451","https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mcr4-qmvw-px4g","description":"yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user"},"relatedVulnerabilities":[{"id":"CVE-2026-106451","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106451","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106451","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106451","date":"2026-10-08","epss":0.00083,"percentile":0.00225}],"urls":["https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3","https://github.com/yawkat/lz4-java/releases/tag/v1.11.4","https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106451","description":"yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4."}]},{"artifact":{"id":"85369d5a3515d91a","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u4","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56132","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-56132","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56132","cwe":"CWE-821","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56132","date":"2026-10-08","epss":0.00103,"percentile":0.00918}],"risk":0.061285000000000006,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56132","description":"In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers."},"relatedVulnerabilities":[{"id":"CVE-2026-56132","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56132","cwe":"CWE-821","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56132","date":"2026-10-08","epss":0.00103,"percentile":0.00918}],"urls":["https://github.com/libexpat/libexpat/pull/1272"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56132","description":"In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers."}]},{"artifact":{"id":"2e0f9dcbf1c8cb58","cpes":["cpe:2.3:a:logback-core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.2.9:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.2.9","type":"java-archive","version":"1.2.9","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"cdaca0cf922c5791a8efa0063ec714ca974affe3","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/logback-core-1.2.9.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6v67-2wr5-gvf4","versionConstraint":"<1.3.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.2.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6v67-2wr5-gvf4","fix":{"state":"fixed","versions":["1.3.15"],"available":[{"date":"2025-01-04","kind":"first-observed","version":"1.3.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H/V:D/U:Clear","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12801","cwe":"CWE-918","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2024-12801","date":"2026-10-08","epss":0.00226,"percentile":0.12203}],"risk":0.06102,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-12801","https://logback.qos.ch/news.html#1.5.13","https://github.com/qos-ch/logback/commit/5f05041cba4c4ac0a62748c5c527a2da48999f2d","https://logback.qos.ch/news.html#1.3.15"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6v67-2wr5-gvf4","description":"QOS.CH logback-core Server-Side Request Forgery vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-12801","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:X/U:Clear","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12801","cwe":"CWE-918","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2024-12801","date":"2026-10-08","epss":0.00226,"percentile":0.12203}],"urls":["https://logback.qos.ch/news.html#1.3.15","https://logback.qos.ch/news.html#1.5.13"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-12801","description":"Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to \nforge requests by compromising logback configuration files in XML.\n\n\n\nThe attacks involves the modification of DOCTYPE declaration in  XML configuration files."}]},{"artifact":{"id":"cd0a6d87e2b9c130","cpes":["cpe:2.3:a:apt:apt:2.6.1:*:*:*:*:*:*:*"],"name":"apt","purl":"pkg:deb/debian/apt@2.6.1?arch=amd64&distro=debian-12.15","type":"deb","version":"2.6.1","language":"","licenses":["BSD-3-clause","Expat","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apt/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/apt/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/apt.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/apt.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/apt.list"},{"path":"/var/lib/dpkg/info/apt.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/apt.postinst"},{"path":"/var/lib/dpkg/info/apt.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/apt.postrm"},{"path":"/var/lib/dpkg/info/apt.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/apt.preinst"},{"path":"/var/lib/dpkg/info/apt.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/apt.prerm"},{"path":"/var/lib/dpkg/info/apt.shlibs","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/apt.shlibs"},{"path":"/var/lib/dpkg/info/apt.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/apt.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2011-3374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"apt","version":"2.6.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2011-3374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3374","date":"2026-10-08","epss":0.01191,"percentile":0.6706}],"risk":0.05955000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3374","description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3374","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3374","date":"2026-10-08","epss":0.01191,"percentile":0.6706}],"urls":["https://access.redhat.com/security/cve/cve-2011-3374","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642480","https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.html","https://seclists.org/fulldisclosure/2011/Sep/221","https://security-tracker.debian.org/tracker/CVE-2011-3374","https://snyk.io/vuln/SNYK-LINUX-APT-116518","https://ubuntu.com/security/CVE-2011-3374"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3374","description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack."}]},{"artifact":{"id":"91b1396a4c2e715d","cpes":["cpe:2.3:a:libapt-pkg6.0:libapt-pkg6.0:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:libapt-pkg6.0:libapt_pkg6.0:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg6.0:libapt-pkg6.0:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg6.0:libapt_pkg6.0:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt-pkg6.0:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt_pkg6.0:2.6.1:*:*:*:*:*:*:*"],"name":"libapt-pkg6.0","purl":"pkg:deb/debian/libapt-pkg6.0@2.6.1?arch=amd64&distro=debian-12.15&upstream=apt","type":"deb","version":"2.6.1","language":"","licenses":["BSD-3-clause","Expat","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapt-pkg6.0/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libapt-pkg6.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapt-pkg6.0:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libapt-pkg6.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"apt"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-3374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"apt","version":"2.6.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2011-3374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3374","date":"2026-10-08","epss":0.01191,"percentile":0.6706}],"risk":0.05955000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3374","description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3374","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3374","date":"2026-10-08","epss":0.01191,"percentile":0.6706}],"urls":["https://access.redhat.com/security/cve/cve-2011-3374","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642480","https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.html","https://seclists.org/fulldisclosure/2011/Sep/221","https://security-tracker.debian.org/tracker/CVE-2011-3374","https://snyk.io/vuln/SNYK-LINUX-APT-116518","https://ubuntu.com/security/CVE-2011-3374"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3374","description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"9db16cb04ae3b83d","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"fb1c9cf5b43a5af0","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"52548f50c4ff26c7","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"309b5ab55a11c7d0","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"df01c68aff59530a","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.10.1-3\\+deb12u1:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/debian/libgcrypt20@1.10.1-3%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.10.1-3+deb12u1","language":"","licenses":["sha256:95db2f9da663f2bfe2aabe9c72fce9d6c9ae767b912f397d7823f50bd55a1a7d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-2236","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libgcrypt20","version":"1.10.1-3+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-2236","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-2236","date":"2026-10-08","epss":0.01114,"percentile":0.65005}],"risk":0.055700000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-2236","description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts."},"relatedVulnerabilities":[{"id":"CVE-2024-2236","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-2236","date":"2026-10-08","epss":0.01114,"percentile":0.65005}],"urls":["https://access.redhat.com/errata/RHSA-2024:9404","https://access.redhat.com/errata/RHSA-2025:3530","https://access.redhat.com/errata/RHSA-2025:3534","https://access.redhat.com/security/cve/CVE-2024-2236","https://bugzilla.redhat.com/show_bug.cgi?id=2245218","https://bugzilla.redhat.com/show_bug.cgi?id=2268268"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2236","description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts."}]},{"artifact":{"id":"bab4532a87a829c8","cpes":["cpe:2.3:a:gpgv:gpgv:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/debian/gpgv@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-68972","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-68972","date":"2026-10-08","epss":0.00113,"percentile":0.01342}],"risk":0.05480499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68972","description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line."},"relatedVulnerabilities":[{"id":"CVE-2025-68972","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-68972","date":"2026-10-08","epss":0.00113,"percentile":0.01342}],"urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line."}]},{"artifact":{"id":"1f7c407a4dbe7f15","cpes":["cpe:2.3:a:golang:x\\/sys:v0.1.0:*:*:*:*:*:*:*"],"name":"golang.org/x/sys","purl":"pkg:golang/golang.org/x/sys@v0.1.0","type":"go-module","version":"v0.1.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:kunALQeHf1/185U1i0GOB/fy1IPRDDpuoOOqRReG57U=","mainModule":"github.com/tianon/gosu","architecture":"amd64","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.44.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5024","versionConstraint":"<0.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/sys","version":"v0.1.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5024","fix":{"state":"fixed","versions":["0.44.0"],"available":[{"date":"2026-04-23","kind":"release","version":"0.44.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"risk":0.04976999999999999,"urls":["https://go.dev/cl/770080","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78916","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."},"relatedVulnerabilities":[{"id":"CVE-2026-39824","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"urls":["https://go.dev/cl/770080","https://go.dev/issue/78916","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg","https://pkg.go.dev/vuln/GO-2026-5024"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39824","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."}]},{"artifact":{"id":"d5e0daed57b0ef5c","cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.13%2Bdfsg1-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-1+deb12u2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-5686","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"shadow","version":"1:4.13+dfsg1-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-5686","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-5686","date":"2026-10-08","epss":0.00942,"percentile":0.59797}],"risk":0.0471,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-5686","description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers."},"relatedVulnerabilities":[{"id":"CVE-2007-5686","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:N/A:N","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-5686","date":"2026-10-08","epss":0.00942,"percentile":0.59797}],"urls":["http://secunia.com/advisories/27215","http://www.securityfocus.com/archive/1/482129/100/100/threaded","http://www.securityfocus.com/archive/1/482857/100/0/threaded","http://www.securityfocus.com/bid/26048","http://www.vupen.com/english/advisories/2007/3474","https://issues.rpath.com/browse/RPL-1825"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-5686","description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers."}]},{"artifact":{"id":"1853000d374a22b0","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-1\\+deb12u2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/debian/passwd@1%3A4.13%2Bdfsg1-1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-1+deb12u2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-5686","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"shadow","version":"1:4.13+dfsg1-1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2007-5686","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-5686","date":"2026-10-08","epss":0.00942,"percentile":0.59797}],"risk":0.0471,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-5686","description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers."},"relatedVulnerabilities":[{"id":"CVE-2007-5686","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:N/A:N","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-5686","date":"2026-10-08","epss":0.00942,"percentile":0.59797}],"urls":["http://secunia.com/advisories/27215","http://www.securityfocus.com/archive/1/482129/100/100/threaded","http://www.securityfocus.com/archive/1/482857/100/0/threaded","http://www.securityfocus.com/bid/26048","http://www.vupen.com/english/advisories/2007/3474","https://issues.rpath.com/browse/RPL-1825"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-5686","description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers."}]},{"artifact":{"id":"58c10ea7ffbc22a3","cpes":["cpe:2.3:a:gcc-12-base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12-base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12_base:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc-12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc_12:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-12-base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_12_base:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"gcc-12-base","purl":"pkg:deb/debian/gcc-12-base@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/gcc-12-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gcc-12-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-27943","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"risk":0.04530000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."},"relatedVulnerabilities":[{"id":"CVE-2022-27943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."}]},{"artifact":{"id":"9454a77b5ea4561d","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-27943","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"risk":0.04530000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."},"relatedVulnerabilities":[{"id":"CVE-2022-27943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."}]},{"artifact":{"id":"c2f4fec51904a8ce","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:12.2.0-14\\+deb12u1:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@12.2.0-14%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=gcc-12","type":"deb","version":"12.2.0-14+deb12u1","language":"","licenses":["sha256:da8191658b3452ce9caf31638ba61dab31a38c619fa39df119812e050f592fd3"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-12-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gcc-12","version":"12.2.0-14+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-27943","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"risk":0.04530000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."},"relatedVulnerabilities":[{"id":"CVE-2022-27943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."}]},{"artifact":{"id":"bab4532a87a829c8","cpes":["cpe:2.3:a:gpgv:gpgv:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/debian/gpgv@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-57062","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-57062","date":"2026-10-08","epss":0.00149,"percentile":0.03583}],"risk":0.043955,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57062","description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182."},"relatedVulnerabilities":[{"id":"CVE-2026-57062","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-57062","date":"2026-10-08","epss":0.00149,"percentile":0.03583}],"urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182."}]},{"artifact":{"id":"fa8be228d5b7724c","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.04378499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"55089f35a6363c37","cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.04378499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.04257,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.  When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.04257,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.  When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"9db16cb04ae3b83d","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"fb1c9cf5b43a5af0","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"52548f50c4ff26c7","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"309b5ab55a11c7d0","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"bab4532a87a829c8","cpes":["cpe:2.3:a:gpgv:gpgv:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/debian/gpgv@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.040589999999999994,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"2e0f9dcbf1c8cb58","cpes":["cpe:2.3:a:logback-core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.2.9:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.2.9:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.2.9","type":"java-archive","version":"1.2.9","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"cdaca0cf922c5791a8efa0063ec714ca974affe3","algorithm":"sha1"}]},"locations":[{"path":"/opt/cassandra/lib/logback-core-1.2.9.jar","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/opt/cassandra/lib/logback-core-1.2.9.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.25"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qqpg-mvqg-649v","versionConstraint":"<1.5.25 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.2.9"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qqpg-mvqg-649v","fix":{"state":"fixed","versions":["1.5.25"],"available":[{"date":"2026-01-23","kind":"first-observed","version":"1.5.25"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1225","cwe":"CWE-20","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-1225","date":"2026-10-08","epss":0.00165,"percentile":0.0518}],"risk":0.039599999999999996,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-1225","https://logback.qos.ch/news.html#1.5.25","https://github.com/qos-ch/logback/issues/997","https://github.com/qos-ch/logback/commit/1f97ae1844b1be8486e4e9cade98d7123d3eded5"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qqpg-mvqg-649v","description":"Logback allows an attacker to instantiate classes already present on the class path"},"relatedVulnerabilities":[{"id":"CVE-2026-1225","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:M/U:Green","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1225","cwe":"CWE-20","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-1225","date":"2026-10-08","epss":0.00165,"percentile":0.0518}],"urls":["https://logback.qos.ch/news.html#1.5.25"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1225","description":"ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.\n\n\n\n\nThe instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must  have write access to a \nconfiguration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado."}]},{"artifact":{"id":"f8ad3f5238dbcf6a","cpes":["cpe:2.3:a:tar:tar:1.34\\+dfsg-1.2\\+deb12u1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.34%2Bdfsg-1.2%2Bdeb12u1?arch=amd64&distro=debian-12.15","type":"deb","version":"1.34+dfsg-1.2+deb12u1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"tar","version":"1.34+dfsg-1.2+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18477","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"risk":0.0376,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."},"relatedVulnerabilities":[{"id":"CVE-2026-18477","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"urls":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.0375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330."},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.0375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330."},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.0375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330."},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.0375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'  filter could be bypassed by a crafted archive where a hardlink  references a symlink stored at a deeper name than the hardlink itself.   The extraction fallback validated the symlink at it's archived location  but recreated it at the hardlink's shallower path, letting a relative  target the filter judged contained escape the destination directory.   This allowed a malicious tar archive to create a symlink pointing  outside the destination, enabling out-of-destination file reads or  writes. This was an incomplete fix of CVE-2025-4330."},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"fa8be228d5b7724c","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-16742","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"risk":0.03334499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"},"relatedVulnerabilities":[{"id":"CVE-2026-16742","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"}]},{"artifact":{"id":"55089f35a6363c37","cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-16742","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"risk":0.03334499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"},"relatedVulnerabilities":[{"id":"CVE-2026-16742","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"}]},{"artifact":{"id":"00b653c92ba9a809","cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"name":"libelf1","purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","type":"deb","version":"0.188-2.1","language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"elfutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1352","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-1352","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1352","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1352","date":"2026-10-08","epss":0.00665,"percentile":0.50251}],"risk":0.03325,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1352","description":"A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue."},"relatedVulnerabilities":[{"id":"CVE-2025-1352","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"impactScore":6.5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1352","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1352","date":"2026-10-08","epss":0.00665,"percentile":0.50251}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15923","https://sourceware.org/bugzilla/show_bug.cgi?id=32650","https://sourceware.org/bugzilla/show_bug.cgi?id=32650#c2","https://vuldb.com/?ctiid.295960","https://vuldb.com/?id.295960","https://vuldb.com/?submit.495965","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1352","description":"A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4602","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4602","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"risk":0.03245,"urls":["https://go.dev/issue/77827","https://go.dev/cl/749480"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened.\n\nThe impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."},"relatedVulnerabilities":[{"id":"CVE-2026-27139","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"urls":["https://go.dev/cl/749480","https://go.dev/issue/77827","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4602"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27139","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.032130000000000006,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear  regular-expression work during dialect sniffing and consume significant  CPU when applications pass unbounded input to csv.Sniffer.sniff()."},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.032130000000000006,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear  regular-expression work during dialect sniffing and consume significant  CPU when applications pass unbounded input to csv.Sniffer.sniff()."},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.032130000000000006,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear  regular-expression work during dialect sniffing and consume significant  CPU when applications pass unbounded input to csv.Sniffer.sniff()."},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.11.2-6+deb12u9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"< 3.11.2-6+deb12u9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"fixed","versions":["3.11.2-6+deb12u9"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"3.11.2-6+deb12u9"}]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.032130000000000006,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear  regular-expression work during dialect sniffing and consume significant  CPU when applications pass unbounded input to csv.Sniffer.sniff()."},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"0d487d9c5e9a860d","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.027285,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"3d449c1cd40f62d0","cpes":["cpe:2.3:a:libc6:libc6:2.36-9\\+deb12u14:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.36-9%2Bdeb12u14?arch=amd64&distro=debian-12.15&upstream=glibc","type":"deb","version":"2.36-9+deb12u14","language":"","licenses":["sha256:40c7e1f2118531f038ca22999bd976901254e1bc5cd1b0f0211bdd064c599987"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"glibc","version":"2.36-9+deb12u14"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.027285,"urls":[],"severity":"Low","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"e272b8e8d5eb9292","cpes":["cpe:2.3:a:perl-base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.36.0-7\\+deb12u3:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.36.0-7%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=perl","type":"deb","version":"5.36.0-7+deb12u3","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","HSIEH-BSD","HSIEH-DERIVATIVE","LGPL-2.1","REGCOMP","REGCOMP,","RRA-KEEP-THIS-NOTICE","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-4116","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"perl","version":"5.36.0-7+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2011-4116","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4116","date":"2026-10-08","epss":0.00524,"percentile":0.42672}],"risk":0.0262,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4116","description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks."},"relatedVulnerabilities":[{"id":"CVE-2011-4116","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:S/C:N/I:P/A:N","metrics":{"baseScore":1.5,"impactScore":2.9,"exploitabilityScore":2.7},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4116","date":"2026-10-08","epss":0.00524,"percentile":0.42672}],"urls":["http://www.openwall.com/lists/oss-security/2011/11/04/2","http://www.openwall.com/lists/oss-security/2011/11/04/4","https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14","https://rt.cpan.org/Public/Bug/Display.html?id=69106","https://seclists.org/oss-sec/2011/q4/238"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4116","description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks."}]},{"artifact":{"id":"fa8be228d5b7724c","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2013-4392","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2013-4392","date":"2026-10-08","epss":0.00468,"percentile":0.38534}],"risk":0.0234,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files."},"relatedVulnerabilities":[{"id":"CVE-2013-4392","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"impactScore":5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2013-4392","date":"2026-10-08","epss":0.00468,"percentile":0.38534}],"urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files."}]},{"artifact":{"id":"55089f35a6363c37","cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2013-4392","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2013-4392","date":"2026-10-08","epss":0.00468,"percentile":0.38534}],"risk":0.0234,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files."},"relatedVulnerabilities":[{"id":"CVE-2013-4392","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"impactScore":5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2013-4392","date":"2026-10-08","epss":0.00468,"percentile":0.38534}],"urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files."}]},{"artifact":{"id":"fbd3380dfe250adc","cpes":["cpe:2.3:a:libssl3:libssl3:3.0.22-1\\~deb12u1:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:deb/debian/libssl3@3.0.22-1~deb12u1?arch=amd64&distro=debian-12.15&upstream=openssl","type":"deb","version":"3.0.22-1~deb12u1","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libssl3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libssl3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-27587","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"openssl","version":"3.0.22-1~deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-27587","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-27587","cwe":"CWE-385","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-27587","date":"2026-10-08","epss":0.00433,"percentile":0.35603}],"risk":0.02165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-27587","description":"OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system."},"relatedVulnerabilities":[{"id":"CVE-2025-27587","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-27587","cwe":"CWE-385","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-27587","date":"2026-10-08","epss":0.00433,"percentile":0.35603}],"urls":["https://github.com/openssl/openssl/issues/24253","https://minerva.crocs.fi.muni.cz"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-27587","description":"OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-0563","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"risk":0.021350000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."},"relatedVulnerabilities":[{"id":"CVE-2022-0563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-0563","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"risk":0.021350000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."},"relatedVulnerabilities":[{"id":"CVE-2022-0563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-0563","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"risk":0.021350000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."},"relatedVulnerabilities":[{"id":"CVE-2022-0563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-0563","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"risk":0.021350000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."},"relatedVulnerabilities":[{"id":"CVE-2022-0563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-0563","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"risk":0.021350000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."},"relatedVulnerabilities":[{"id":"CVE-2022-0563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-0563","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"risk":0.021350000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."},"relatedVulnerabilities":[{"id":"CVE-2022-0563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-0563","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"risk":0.021350000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."},"relatedVulnerabilities":[{"id":"CVE-2022-0563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0563","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-0563","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"risk":0.021350000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."},"relatedVulnerabilities":[{"id":"CVE-2022-0563","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0563","cwe":"CWE-209","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0563","date":"2026-10-08","epss":0.00427,"percentile":0.34933}],"urls":["https://lore.kernel.org/util-linux/20220214110609.msiwlm457ngoic6w%40ws.net.home/T/#u","https://security.gentoo.org/glsa/202401-08","https://security.netapp.com/advisory/ntap-20220331-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0563","description":"A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an \"INPUTRC\" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4."}]},{"artifact":{"id":"85369d5a3515d91a","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.5.0-1\\+deb12u4:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.5.0-1%2Bdeb12u4?arch=amd64&distro=debian-12.15&upstream=expat","type":"deb","version":"2.5.0-1+deb12u4","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-52426","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"expat","version":"2.5.0-1+deb12u4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-52426","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-52426","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-52426","cwe":"CWE-776","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-52426","date":"2026-10-08","epss":0.00373,"percentile":0.29104}],"risk":0.01865,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-52426","description":"libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time."},"relatedVulnerabilities":[{"id":"CVE-2023-52426","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-52426","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-52426","cwe":"CWE-776","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-52426","date":"2026-10-08","epss":0.00373,"percentile":0.29104}],"urls":["https://cwe.mitre.org/data/definitions/776.html","https://github.com/libexpat/libexpat/commit/0f075ec8ecb5e43f8fdca5182f8cca4703da0404","https://github.com/libexpat/libexpat/pull/777","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNUBSGZFEZOBHJFTAD42SAN4ATW2VEMV/","https://security.netapp.com/advisory/ntap-20240307-0005/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-52426","description":"libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time."}]},{"artifact":{"id":"00b653c92ba9a809","cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"name":"libelf1","purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","type":"deb","version":"0.188-2.1","language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"elfutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1372","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-1372","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1372","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1372","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1372","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1372","date":"2026-10-08","epss":0.00349,"percentile":0.26487}],"risk":0.01745,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1372","description":"A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf. The manipulation of the argument z/x leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 73db9d2021cab9e23fd734b0a76a612d52a6f1db. It is recommended to apply a patch to fix this issue."},"relatedVulnerabilities":[{"id":"CVE-2025-1372","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1372","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1372","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1372","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1372","date":"2026-10-08","epss":0.00349,"percentile":0.26487}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15927","https://sourceware.org/bugzilla/show_bug.cgi?id=32656","https://sourceware.org/bugzilla/show_bug.cgi?id=32656#c3","https://sourceware.org/bugzilla/show_bug.cgi?id=32657","https://vuldb.com/?ctiid.295981","https://vuldb.com/?id.295981","https://vuldb.com/?submit.496485","https://www.gnu.org/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1372","description":"A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf. The manipulation of the argument z/x leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 73db9d2021cab9e23fd734b0a76a612d52a6f1db. It is recommended to apply a patch to fix this issue."}]},{"artifact":{"id":"fa8be228d5b7724c","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-31439","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31439","date":"2026-10-08","epss":0.00349,"percentile":0.26446}],"risk":0.01745,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31439","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31439","date":"2026-10-08","epss":0.00349,"percentile":0.26446}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"55089f35a6363c37","cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-31439","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31439","date":"2026-10-08","epss":0.00349,"percentile":0.26446}],"risk":0.01745,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31439","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31439","date":"2026-10-08","epss":0.00349,"percentile":0.26446}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"00b653c92ba9a809","cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"name":"libelf1","purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","type":"deb","version":"0.188-2.1","language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"elfutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1365","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-1365","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1365","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1365","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1365","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1365","date":"2026-10-08","epss":0.00345,"percentile":0.26002}],"risk":0.01725,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1365","description":"A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The manipulation of the argument D/a leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5e5c0394d82c53e97750fe7b18023e6f84157b81. It is recommended to apply a patch to fix this issue."},"relatedVulnerabilities":[{"id":"CVE-2025-1365","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1365","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1365","cwe":"CWE-120","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1365","cwe":"CWE-120","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1365","date":"2026-10-08","epss":0.00345,"percentile":0.26002}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15925","https://sourceware.org/bugzilla/show_bug.cgi?id=32654","https://sourceware.org/bugzilla/show_bug.cgi?id=32654#c2","https://vuldb.com/?ctiid.295977","https://vuldb.com/?id.295977","https://vuldb.com/?submit.496483","https://www.gnu.org/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1365","description":"A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The manipulation of the argument D/a leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5e5c0394d82c53e97750fe7b18023e6f84157b81. It is recommended to apply a patch to fix this issue."}]},{"artifact":{"id":"eca37691b87c0860","cpes":["cpe:2.3:a:coreutils:coreutils:9.1-1:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.15","type":"deb","version":"9.1-1","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.list"},{"path":"/var/lib/dpkg/info/coreutils.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.postinst"},{"path":"/var/lib/dpkg/info/coreutils.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.postrm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2017-18018","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"coreutils","version":"9.1-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2017-18018","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-18018","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2017-18018","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2017-18018","date":"2026-10-08","epss":0.00345,"percentile":0.25992}],"risk":0.01725,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-18018","description":"In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition."},"relatedVulnerabilities":[{"id":"CVE-2017-18018","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-18018","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2017-18018","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2017-18018","date":"2026-10-08","epss":0.00345,"percentile":0.25992}],"urls":["http://lists.gnu.org/archive/html/coreutils/2017-12/msg00045.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-18018","description":"In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition."}]},{"artifact":{"id":"fa8be228d5b7724c","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-31437","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31437","date":"2026-10-08","epss":0.00341,"percentile":0.25569}],"risk":0.01705,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31437","date":"2026-10-08","epss":0.00341,"percentile":0.25569}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"55089f35a6363c37","cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-31437","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31437","date":"2026-10-08","epss":0.00341,"percentile":0.25569}],"risk":0.01705,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31437","date":"2026-10-08","epss":0.00341,"percentile":0.25569}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"eae3581d3fe173ec","cpes":["cpe:2.3:a:diffutils:diffutils:1\\:3.8-4:*:*:*:*:*:*:*"],"name":"diffutils","purl":"pkg:deb/debian/diffutils@1%3A3.8-4?arch=amd64&distro=debian-12.15","type":"deb","version":"1:3.8-4","language":"","licenses":["FSFAP","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3.0+","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/diffutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/diffutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/diffutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/diffutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/diffutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/diffutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"diffutils","version":"1:3.8-4"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53910","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-53910","date":"2026-10-08","epss":0.00332,"percentile":0.24312}],"risk":0.016600000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53910","description":"diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing.  An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.   This issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815   NOTE: The project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges."},"relatedVulnerabilities":[{"id":"CVE-2026-53910","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53910","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-53910","date":"2026-10-08","epss":0.00332,"percentile":0.24312}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-53910","https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50","https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815","https://git.savannah.gnu.org/cgit/diffutils.git/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53910","description":"diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds.\nWhen processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing. \nAn attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.\n\n\nThis issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815 \n\nNOTE:\nThe project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges."}]},{"artifact":{"id":"00b653c92ba9a809","cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"name":"libelf1","purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","type":"deb","version":"0.188-2.1","language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"elfutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1377","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-1377","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1377","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1377","date":"2026-10-08","epss":0.00326,"percentile":0.23639}],"risk":0.016300000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1377","description":"A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue."},"relatedVulnerabilities":[{"id":"CVE-2025-1377","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1377","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1377","date":"2026-10-08","epss":0.00326,"percentile":0.23639}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15941","https://sourceware.org/bugzilla/show_bug.cgi?id=32673","https://sourceware.org/bugzilla/show_bug.cgi?id=32673#c2","https://vuldb.com/?ctiid.295985","https://vuldb.com/?id.295985","https://vuldb.com/?submit.497539","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1377","description":"A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue."}]},{"artifact":{"id":"fa8be228d5b7724c","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-31438","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31438","date":"2026-10-08","epss":0.00325,"percentile":0.23574}],"risk":0.01625,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31438","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31438","date":"2026-10-08","epss":0.00325,"percentile":0.23574}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"55089f35a6363c37","cpes":["cpe:2.3:a:libudev1:libudev1:252.39-1\\~deb12u2:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/debian/libudev1@252.39-1~deb12u2?arch=amd64&distro=debian-12.15&upstream=systemd","type":"deb","version":"252.39-1~deb12u2","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"systemd","version":"252.39-1~deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2023-31438","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31438","date":"2026-10-08","epss":0.00325,"percentile":0.23574}],"risk":0.01625,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31438","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31438","date":"2026-10-08","epss":0.00325,"percentile":0.23574}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"00b653c92ba9a809","cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"name":"libelf1","purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","type":"deb","version":"0.188-2.1","language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"elfutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1376","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-1376","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1376","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1376","date":"2026-10-08","epss":0.00309,"percentile":0.2173}],"risk":0.015450000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1376","description":"A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue."},"relatedVulnerabilities":[{"id":"CVE-2025-1376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:H/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1,"impactScore":2.9,"exploitabilityScore":1.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1376","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-1376","date":"2026-10-08","epss":0.00309,"percentile":0.2173}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15940","https://sourceware.org/bugzilla/show_bug.cgi?id=32672","https://sourceware.org/bugzilla/show_bug.cgi?id=32672#c3","https://vuldb.com/?ctiid.295984","https://vuldb.com/?id.295984","https://vuldb.com/?submit.497538","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1376","description":"A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue."}]},{"artifact":{"id":"00b653c92ba9a809","cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"name":"libelf1","purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","type":"deb","version":"0.188-2.1","language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"elfutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-25260","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2024-25260","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-25260","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-25260","date":"2026-10-08","epss":0.00307,"percentile":0.21511}],"risk":0.015349999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-25260","description":"elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c."},"relatedVulnerabilities":[{"id":"CVE-2024-25260","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-25260","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-25260","date":"2026-10-08","epss":0.00307,"percentile":0.21511}],"urls":["https://github.com/schsiung/fuzzer_issues/issues/1","https://sourceware.org/bugzilla/show_bug.cgi?id=31058","https://sourceware.org/elfutils/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-25260","description":"elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-70873","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-70873","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-70873","cwe":"CWE-244","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-70873","date":"2026-10-08","epss":0.00301,"percentile":0.20911}],"risk":0.015050000000000003,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-70873","description":"An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file."},"relatedVulnerabilities":[{"id":"CVE-2025-70873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-70873","cwe":"CWE-244","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-70873","date":"2026-10-08","epss":0.00301,"percentile":0.20911}],"urls":["https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054","https://sqlite.org/forum/forumpost/761eac3c82","https://sqlite.org/src/info/3d459f1fb1bd1b5e"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-70873","description":"An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file."}]},{"artifact":{"id":"bab4532a87a829c8","cpes":["cpe:2.3:a:gpgv:gpgv:2.2.40-1.1\\+deb12u2:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/debian/gpgv@2.2.40-1.1%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=gnupg2","type":"deb","version":"2.2.40-1.1+deb12u2","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"gnupg2","version":"2.2.40-1.1+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.014650000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"eca37691b87c0860","cpes":["cpe:2.3:a:coreutils:coreutils:9.1-1:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.15","type":"deb","version":"9.1-1","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.list"},{"path":"/var/lib/dpkg/info/coreutils.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.postinst"},{"path":"/var/lib/dpkg/info/coreutils.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.postrm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5278","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"coreutils","version":"9.1-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-5278","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-5278","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5278","date":"2026-10-08","epss":0.00288,"percentile":0.19615}],"risk":0.0144,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-5278","description":"A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data."},"relatedVulnerabilities":[{"id":"CVE-2025-5278","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5278","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5278","date":"2026-10-08","epss":0.00288,"percentile":0.19615}],"urls":["https://access.redhat.com/errata/RHSA-2026:28911","https://access.redhat.com/errata/RHSA-2026:33124","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:33612","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:69964","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2025-5278","https://bugzilla.redhat.com/show_bug.cgi?id=2368764","https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507","http://www.openwall.com/lists/oss-security/2025/05/27/2","http://www.openwall.com/lists/oss-security/2025/05/29/1","http://www.openwall.com/lists/oss-security/2025/05/29/2","https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14","https://security-tracker.debian.org/tracker/CVE-2025-5278"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5278","description":"A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data."}]},{"artifact":{"id":"9db16cb04ae3b83d","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11850","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-08","epss":0.00271,"percentile":0.17713}],"risk":0.013550000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."},"relatedVulnerabilities":[{"id":"CVE-2026-11850","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-08","epss":0.00271,"percentile":0.17713}],"urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."}]},{"artifact":{"id":"fb1c9cf5b43a5af0","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11850","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-08","epss":0.00271,"percentile":0.17713}],"risk":0.013550000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."},"relatedVulnerabilities":[{"id":"CVE-2026-11850","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-08","epss":0.00271,"percentile":0.17713}],"urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."}]},{"artifact":{"id":"52548f50c4ff26c7","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11850","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-08","epss":0.00271,"percentile":0.17713}],"risk":0.013550000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."},"relatedVulnerabilities":[{"id":"CVE-2026-11850","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-08","epss":0.00271,"percentile":0.17713}],"urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."}]},{"artifact":{"id":"309b5ab55a11c7d0","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.20.1-2\\+deb12u5:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.20.1-2%2Bdeb12u5?arch=amd64&distro=debian-12.15&upstream=krb5","type":"deb","version":"1.20.1-2+deb12u5","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"krb5","version":"1.20.1-2+deb12u5"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-11850","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-08","epss":0.00271,"percentile":0.17713}],"risk":0.013550000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."},"relatedVulnerabilities":[{"id":"CVE-2026-11850","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-08","epss":0.00271,"percentile":0.17713}],"urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3479","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"risk":0.01225,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals."},"relatedVulnerabilities":[{"id":"CVE-2026-3479","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"severity":"Negligible","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3479","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"risk":0.01225,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals."},"relatedVulnerabilities":[{"id":"CVE-2026-3479","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"severity":"Negligible","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3479","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"risk":0.01225,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals."},"relatedVulnerabilities":[{"id":"CVE-2026-3479","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"severity":"Negligible","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3479","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-3479","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"risk":0.01225,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3479","description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.  pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals."},"relatedVulnerabilities":[{"id":"CVE-2026-3479","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":0},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3479","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3479","date":"2026-10-08","epss":0.00245,"percentile":0.14394}],"urls":["https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fe","https://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7","https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943","https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59c","https://github.com/python/cpython/issues/146121","https://github.com/python/cpython/pull/146122","https://mail.python.org/archives/list/security-announce@python.org/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/"],"severity":"Negligible","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3479","description":"DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.\n\npkgutil.get_data() did not validate the resource argument as documented, allowing path traversals."}]},{"artifact":{"id":"7f93d91040ef0939","cpes":["cpe:2.3:a:libbpf1:libbpf1:1\\:1.1.2-0\\+deb12u1:*:*:*:*:*:*:*"],"name":"libbpf1","purl":"pkg:deb/debian/libbpf1@1%3A1.1.2-0%2Bdeb12u1?arch=amd64&distro=debian-12.15&upstream=libbpf%401.1.2-0%2Bdeb12u1","type":"deb","version":"1:1.1.2-0+deb12u1","language":"","licenses":["GPL-2","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbpf1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libbpf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbpf1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libbpf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libbpf","version":"1.1.2-0+deb12u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-29481","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"libbpf","version":"1.1.2-0+deb12u1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-29481","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-29481","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-29481","date":"2026-10-08","epss":0.00239,"percentile":0.13762}],"risk":0.011950000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-29481","description":"Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that \"no one in their sane mind should be passing untrusted ELF files into libbpf while running under root.\""},"relatedVulnerabilities":[{"id":"CVE-2025-29481","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-29481","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-29481","date":"2026-10-08","epss":0.00239,"percentile":0.13762}],"urls":["https://github.com/lmarch2/poc/blob/main/libbpf/libbpf.md"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-29481","description":"Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that \"no one in their sane mind should be passing untrusted ELF files into libbpf while running under root.\""}]},{"artifact":{"id":"00b653c92ba9a809","cpes":["cpe:2.3:a:libelf1:libelf1:0.188-2.1:*:*:*:*:*:*:*"],"name":"libelf1","purl":"pkg:deb/debian/libelf1@0.188-2.1?arch=amd64&distro=debian-12.15&upstream=elfutils","type":"deb","version":"0.188-2.1","language":"","licenses":["BSD-2-clause","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libelf1/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libelf1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libelf1:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libelf1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"elfutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-1371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"elfutils","version":"0.188-2.1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-1371","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-1371","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1371","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1371","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1371","date":"2026-10-08","epss":0.00233,"percentile":0.13042}],"risk":0.01165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-1371","description":"A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue."},"relatedVulnerabilities":[{"id":"CVE-2025-1371","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1371","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1371","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1371","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1371","date":"2026-10-08","epss":0.00233,"percentile":0.13042}],"urls":["https://sourceware.org/bugzilla/attachment.cgi?id=15926","https://sourceware.org/bugzilla/show_bug.cgi?id=32655","https://sourceware.org/bugzilla/show_bug.cgi?id=32655#c2","https://vuldb.com/?ctiid.295978","https://vuldb.com/?id.295978","https://vuldb.com/?submit.496484","https://www.gnu.org/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1371","description":"A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue."}]},{"artifact":{"id":"3705ae977c727f09","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.40.1-2\\+deb12u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.40.1-2%2Bdeb12u2?arch=amd64&distro=debian-12.15&upstream=sqlite3","type":"deb","version":"3.40.1-2+deb12u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-29088","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"sqlite3","version":"3.40.1-2+deb12u2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-29088","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-29088","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-29088","date":"2026-10-08","epss":0.00217,"percentile":0.11133}],"risk":0.01085,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-29088","description":"In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect."},"relatedVulnerabilities":[{"id":"CVE-2025-29088","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-29088","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-29088","date":"2026-10-08","epss":0.00217,"percentile":0.11133}],"urls":["https://gist.github.com/ylwango613/d3883fb9f6ba8a78086356779ce88248","https://github.com/sqlite/sqlite/commit/56d2fd008b108109f489339f5fd55212bb50afd4","https://sqlite.org/forum/forumpost/48f365daec","https://sqlite.org/releaselog/3_49_1.html","https://www.sqlite.org/cves.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-29088","description":"In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-14104","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"risk":0.009650000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."},"relatedVulnerabilities":[{"id":"CVE-2025-14104","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-14104","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"risk":0.009650000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."},"relatedVulnerabilities":[{"id":"CVE-2025-14104","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-14104","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"risk":0.009650000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."},"relatedVulnerabilities":[{"id":"CVE-2025-14104","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-14104","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"risk":0.009650000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."},"relatedVulnerabilities":[{"id":"CVE-2025-14104","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-14104","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"risk":0.009650000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."},"relatedVulnerabilities":[{"id":"CVE-2025-14104","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-14104","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"risk":0.009650000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."},"relatedVulnerabilities":[{"id":"CVE-2025-14104","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-14104","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"risk":0.009650000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."},"relatedVulnerabilities":[{"id":"CVE-2025-14104","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14104","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2025-14104","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"risk":0.009650000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."},"relatedVulnerabilities":[{"id":"CVE-2025-14104","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14104","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14104","date":"2026-10-08","epss":0.00193,"percentile":0.08198}],"urls":["https://access.redhat.com/errata/RHSA-2026:1696","https://access.redhat.com/errata/RHSA-2026:1852","https://access.redhat.com/errata/RHSA-2026:1913","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2737","https://access.redhat.com/errata/RHSA-2026:2800","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2025-14104","https://bugzilla.redhat.com/show_bug.cgi?id=2419369"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14104","description":"A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database."}]},{"artifact":{"id":"eca37691b87c0860","cpes":["cpe:2.3:a:coreutils:coreutils:9.1-1:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.15","type":"deb","version":"9.1-1","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.list"},{"path":"/var/lib/dpkg/info/coreutils.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.postinst"},{"path":"/var/lib/dpkg/info/coreutils.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.postrm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56392","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"coreutils","version":"9.1-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.009300000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.  When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.           This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[{"id":"CVE-2026-56392","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"}]},{"artifact":{"id":"eca37691b87c0860","cpes":["cpe:2.3:a:coreutils:coreutils:9.1-1:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/debian/coreutils@9.1-1?arch=amd64&distro=debian-12.15","type":"deb","version":"9.1-1","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.list"},{"path":"/var/lib/dpkg/info/coreutils.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.postinst"},{"path":"/var/lib/dpkg/info/coreutils.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/coreutils.postrm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56391","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"coreutils","version":"9.1-1"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.00855,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value.  This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.  When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.   This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[{"id":"CVE-2026-56391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."}]},{"artifact":{"id":"1fa5bad162623b66","cpes":["cpe:2.3:a:libpython3.11-minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_minimal:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-minimal","purl":"pkg:deb/debian/libpython3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-12003","date":"2026-10-08","epss":0.00147,"percentile":0.03431}],"risk":0.00735,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer."},"relatedVulnerabilities":[{"id":"CVE-2026-12003","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-12003","date":"2026-10-08","epss":0.00147,"percentile":0.03431}],"urls":["https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06","https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/872038377db2e170e0e140b5f8aaedf636b3fbf5","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer."}]},{"artifact":{"id":"f5f8c195b69e3ce5","cpes":["cpe:2.3:a:libpython3.11-stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11-stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11_stdlib:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11-stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.11:libpython3.11_stdlib:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"libpython3.11-stdlib","purl":"pkg:deb/debian/libpython3.11-stdlib@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/libpython3.11-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/libpython3.11-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-12003","date":"2026-10-08","epss":0.00147,"percentile":0.03431}],"risk":0.00735,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer."},"relatedVulnerabilities":[{"id":"CVE-2026-12003","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-12003","date":"2026-10-08","epss":0.00147,"percentile":0.03431}],"urls":["https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06","https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/872038377db2e170e0e140b5f8aaedf636b3fbf5","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer."}]},{"artifact":{"id":"a09824e123a98184","cpes":["cpe:2.3:a:python3.11:python3.11:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11","purl":"pkg:deb/debian/python3.11@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.list"},{"path":"/var/lib/dpkg/info/python3.11.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.postinst"},{"path":"/var/lib/dpkg/info/python3.11.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-12003","date":"2026-10-08","epss":0.00147,"percentile":0.03431}],"risk":0.00735,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer."},"relatedVulnerabilities":[{"id":"CVE-2026-12003","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-12003","date":"2026-10-08","epss":0.00147,"percentile":0.03431}],"urls":["https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06","https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/872038377db2e170e0e140b5f8aaedf636b3fbf5","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer."}]},{"artifact":{"id":"cc97519512dedbd9","cpes":["cpe:2.3:a:python3.11-minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11-minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11_minimal:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11-minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*","cpe:2.3:a:python3.11:python3.11_minimal:3.11.2-6\\+deb12u8:*:*:*:*:*:*:*"],"name":"python3.11-minimal","purl":"pkg:deb/debian/python3.11-minimal@3.11.2-6%2Bdeb12u8?arch=amd64&distro=debian-12.15&upstream=python3.11","type":"deb","version":"3.11.2-6+deb12u8","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.11-minimal/copyright","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/usr/share/doc/python3.11-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.md5sums","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.11-minimal.list","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.list"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.postrm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.11-minimal.preinst","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.11-minimal.prerm","layerID":"sha256:d2f6660664b6ed045bcaf4c742d17ae88625a9479e1f80b9e34a76f19326b719","accessPath":"/var/lib/dpkg/info/python3.11-minimal.prerm"}],"upstreams":[{"name":"python3.11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12003","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"python3.11","version":"3.11.2-6+deb12u8"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-12003","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-12003","date":"2026-10-08","epss":0.00147,"percentile":0.03431}],"risk":0.00735,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12003","description":"To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.  On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\\..', which results in a landmark of '..\\..\\Modules\\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install.  Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.  Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.  Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.  The landmark detection involving VPATH is a fallback for when a more specific landmark - .\\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer."},"relatedVulnerabilities":[{"id":"CVE-2026-12003","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12003","cwe":"CWE-427","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-12003","date":"2026-10-08","epss":0.00147,"percentile":0.03431}],"urls":["https://github.com/python/cpython/commit/03ab7b44788bfd6b8927e16bcdbd025aa08dce06","https://github.com/python/cpython/commit/16c40f944b7bff724a403cf4902763d095bb4b2a","https://github.com/python/cpython/commit/872038377db2e170e0e140b5f8aaedf636b3fbf5","https://github.com/python/cpython/commit/9e863fab283eddca9c2a8f9d1ee30f4dc243e314","https://github.com/python/cpython/commit/a86de0bc236fbb9452f98998fc8437e9fca35700","https://github.com/python/cpython/commit/b93d6d3399adbd3a5037b6b92fc3587c85ac5d56","https://github.com/python/cpython/issues/151544","https://github.com/python/cpython/pull/151545","https://https://mail.python.org/archives/list/security-announce@python.org/thread/JIFOBO7UX3LY4VJKJUOKYJV62CFR2IRH/","http://www.openwall.com/lists/oss-security/2026/06/16/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12003","description":"To allow builds of Python to be run from an in-tree layout (rather than\nan installed file layout), the VPATH variable is defined at build time\nand used to locate certain landmarks - specifically,\nModules/setup.local. When this landmark is found relative to VPATH\nrelative to the executable, Python assumes it is running in a source\ntree and generates a different default sys.path. This code remains in\nrelease builds, so that release-ready builds can be built in-tree.\n\nOn Windows, since builds are written to 'PCbuild/', the value of\nVPATH is set to '..\\..', which results in a landmark of\n'..\\..\\Modules\\setup.local'. This path is outside the install directory\nof Python, and may have different permissions, potentially allowing a\nlow-privilege user to create the landmark and an alternative `Lib`\nfolder that will be discovered by an otherwise restricted install.\n\nSuch a setup occurs with the legacy default install location for all\nusers (in the now superseded EXE installer), due to how Windows allows\nall users to create folders in the root directory of their OS drive.\n\nOur recommended mitigation on Windows is to migrate away from the\nlegacy installer and use the new [Python install\nmanager](https://www.python.org/downloads/latest/pymanager/) to install\nfor the current user. Installs where the directory two levels above the\nPython installation directory have equivalent permissions are unaffected\n(in general, a per-user install cannot be modified at all by other\nusers, removing any escalation of privilege risk, and could be directly\nmodified by a privileged user, making the potential tampering\nirrelevant). Alternative mitigations might include preemptively creating\nand restricting access to a `Modules` directory. Be aware that only 3.13\nand 3.14 will receive updated legacy installers - earlier fixes are only\nprovided as sources.\n\nPlatforms other than Windows allow VPATH to be overridden, but as they\ndon't usually use a separated directory in the build for binaries, are\nunlikely to have a landmark reference outside of the install directory.\n\nThe landmark detection involving VPATH is a fallback for when a more\nspecific landmark - .\\pybuilddir.txt - is absent, and was included for\ncompatibility. Future releases of Python will no longer include the\nfallback, and so builds will need to generate or preserve the\npybuilddir.txt file in order to work in-tree. This landmark file has\nbeen generated on Windows since 3.11, and on other platforms for longer."}]},{"artifact":{"id":"d99eda363265247f","cpes":["cpe:2.3:a:dash:dash:0.5.12-2:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/debian/dash@0.5.12-2?arch=amd64&distro=debian-12.15","type":"deb","version":"0.5.12-2","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102474","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"dash","version":"0.5.12-2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-102474","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"risk":0.0072,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102474","description":"A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \\u or \\U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation."},"relatedVulnerabilities":[{"id":"CVE-2026-102474","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102474","https://bugzilla.redhat.com/show_bug.cgi?id=2543004"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102474","description":"A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \\u or \\U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation."}]},{"artifact":{"id":"d99eda363265247f","cpes":["cpe:2.3:a:dash:dash:0.5.12-2:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/debian/dash@0.5.12-2?arch=amd64&distro=debian-12.15","type":"deb","version":"0.5.12-2","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102473","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"dash","version":"0.5.12-2"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-102473","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"risk":0.0065,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102473","description":"A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-102473","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102473","https://bugzilla.redhat.com/show_bug.cgi?id=2543005"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102473","description":"A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU."}]},{"artifact":{"id":"d2a8da7f933cc6b6","cpes":["cpe:2.3:a:moby:sys\\/user:v0.1.0:*:*:*:*:*:*:*"],"name":"github.com/moby/sys/user","purl":"pkg:golang/github.com/moby/sys/user@v0.1.0","type":"go-module","version":"v0.1.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:WmZ93f5Ux6het5iituh9x2zAG7NFY9Aqi49jjE1PaQg=","mainModule":"github.com/tianon/gosu","architecture":"amd64","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.4.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mjcv-p78q-w5fw","versionConstraint":"<=0.4.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/moby/sys/user","version":"v0.1.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-mjcv-p78q-w5fw","fix":{"state":"fixed","versions":["0.4.1"],"available":[{"date":"2026-10-08","kind":"first-observed","version":"0.4.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61801","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"risk":0,"urls":["https://github.com/moby/sys/security/advisories/GHSA-mjcv-p78q-w5fw","https://github.com/moby/sys/pull/221","https://github.com/moby/sys/commit/85a71bbe1faa36c552a960e6a5f3d0cfb632fbbe"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mjcv-p78q-w5fw","description":"github.com/moby/sys/user has a possible DoS via unbounded parsing of user and group database files"},"relatedVulnerabilities":[{"id":"CVE-2026-61801","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61801","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"urls":["https://github.com/moby/sys/commit/85a71bbe1faa36c552a960e6a5f3d0cfb632fbbe","https://github.com/moby/sys/pull/221","https://github.com/moby/sys/security/advisories/GHSA-mjcv-p78q-w5fw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61801","description":"The `github.com/moby/sys/user` package provides Go utilities for parsing and looking up entries in Unix-style user and group database files. Versions before 0.4.1 do not sufficiently limit entries when parsing `/etc/passwd`- or `/etc/group`-style files, allowing an attacker who can supply a specially crafted file to cause excessive memory consumption and potentially terminate the affected process due to an out-of-memory condition. This issue is patched in version 0.4.1. As a workaround, avoid parsing attacker-controlled user or group database files, or validate and limit untrusted input before parsing it."}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"f131145b816a43ee","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux%402.38.1-5%2Bdeb12u3","type":"deb","version":"1:2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.38.1-5+deb12u3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"af35543f081d70bf","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"3578a81ebb651f3d","cpes":["cpe:2.3:a:libmount1:libmount1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"ecee94562f1ce06f","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"2049f4c13963925a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"e75e0a2b6968d414","cpes":["cpe:2.3:a:mount:mount:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"c5726b35636bdfbb","cpes":["cpe:2.3:a:golang:go:1.24.6:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.6","type":"go-module","version":"go1.24.6","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.6"},"locations":[{"path":"/usr/local/bin/gosu","layerID":"sha256:57e2afcfba796ecdde5ff15d598259429013b36dcdd75de496e69942f88c0495","accessPath":"/usr/local/bin/gosu","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"b11f4a313957922c","cpes":["cpe:2.3:a:util-linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"fc9180bcad1f4d49","cpes":["cpe:2.3:a:util-linux-extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_extra:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_extra:2.38.1-5\\+deb12u3:*:*:*:*:*:*:*"],"name":"util-linux-extra","purl":"pkg:deb/debian/util-linux-extra@2.38.1-5%2Bdeb12u3?arch=amd64&distro=debian-12.15&upstream=util-linux","type":"deb","version":"2.38.1-5+deb12u3","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:38d5225b3e85973a852296f6dbf3a344da5671a75b5b7866eb9fddf4d1705ca6","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux-extra/copyright","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/usr/share/doc/util-linux-extra/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.conffiles","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.md5sums","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux-extra.list","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.list"},{"path":"/var/lib/dpkg/info/util-linux-extra.postinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postinst"},{"path":"/var/lib/dpkg/info/util-linux-extra.postrm","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.postrm"},{"path":"/var/lib/dpkg/info/util-linux-extra.preinst","layerID":"sha256:e58989146fcec76699871403b9897b5c014af1ccd85f5a9300a215e7975525d7","accessPath":"/var/lib/dpkg/info/util-linux-extra.preinst"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"12.15"},"package":{"name":"util-linux","version":"2.38.1-5+deb12u3"},"namespace":"debian:distro:debian:12"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"debian:distro:debian:12","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T23:46:00.192Z","grype_db_version":"2026-10-09T06:32:32.000Z"}