{"grype_matches":[{"artifact":{"id":"809ea4b423ef5f0e","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u4:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u4","language":"","licenses":["sha256:a07e99815cf1998f1dabbc21fe199460bfa09b85ead0d56b49a32cac3d1791b5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-3389","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2011-3389","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"risk":3.66635,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"urls":["http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/","http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx","http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx","http://curl.haxx.se/docs/adv_20120124B.html","http://downloads.asterisk.org/pub/security/AST-2016-001.html","http://ekoparty.org/2011/juliano-rizzo.php","http://eprint.iacr.org/2004/111","http://eprint.iacr.org/2006/136","http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html","http://isc.sans.edu/diary/SSL+TLS+part+3+/11635","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html","http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html","http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html","http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://marc.info/?l=bugtraq&m=132750579901589&w=2","http://marc.info/?l=bugtraq&m=132872385320240&w=2","http://marc.info/?l=bugtraq&m=133365109612558&w=2","http://marc.info/?l=bugtraq&m=133728004526190&w=2","http://marc.info/?l=bugtraq&m=134254866602253&w=2","http://marc.info/?l=bugtraq&m=134254957702612&w=2","http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue","http://osvdb.org/74829","http://rhn.redhat.com/errata/RHSA-2012-0508.html","http://rhn.redhat.com/errata/RHSA-2013-1455.html","http://secunia.com/advisories/45791","http://secunia.com/advisories/47998","http://secunia.com/advisories/48256","http://secunia.com/advisories/48692","http://secunia.com/advisories/48915","http://secunia.com/advisories/48948","http://secunia.com/advisories/49198","http://secunia.com/advisories/55322","http://secunia.com/advisories/55350","http://secunia.com/advisories/55351","http://security.gentoo.org/glsa/glsa-201203-02.xml","http://security.gentoo.org/glsa/glsa-201406-32.xml","http://support.apple.com/kb/HT4999","http://support.apple.com/kb/HT5001","http://support.apple.com/kb/HT5130","http://support.apple.com/kb/HT5281","http://support.apple.com/kb/HT5501","http://support.apple.com/kb/HT6150","http://technet.microsoft.com/security/advisory/2588513","http://vnhacker.blogspot.com/2011/09/beast.html","http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf","http://www.debian.org/security/2012/dsa-2398","http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html","http://www.ibm.com/developerworks/java/jdk/alerts/","http://www.imperialviolet.org/2011/09/23/chromeandbeast.html","http://www.insecure.cl/Beast-SSL.rar","http://www.kb.cert.org/vuls/id/864643","http://www.mandriva.com/security/advisories?name=MDVSA-2012:058","http://www.opera.com/docs/changelogs/mac/1151/","http://www.opera.com/docs/changelogs/mac/1160/","http://www.opera.com/docs/changelogs/unix/1151/","http://www.opera.com/docs/changelogs/unix/1160/","http://www.opera.com/docs/changelogs/windows/1151/","http://www.opera.com/docs/changelogs/windows/1160/","http://www.opera.com/support/kb/view/1004/","http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html","http://www.redhat.com/support/errata/RHSA-2011-1384.html","http://www.redhat.com/support/errata/RHSA-2012-0006.html","http://www.securityfocus.com/bid/49388","http://www.securityfocus.com/bid/49778","http://www.securitytracker.com/id/1029190","http://www.securitytracker.com/id?1025997","http://www.securitytracker.com/id?1026103","http://www.securitytracker.com/id?1026704","http://www.ubuntu.com/usn/USN-1263-1","http://www.us-cert.gov/cas/techalerts/TA12-010A.html","https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail","https://bugzilla.novell.com/show_bug.cgi?id=719047","https://bugzilla.redhat.com/show_bug.cgi?id=737506","https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006","https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862","https://hermes.opensuse.org/messages/13154861","https://hermes.opensuse.org/messages/13155432","https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4341","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4341","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"risk":1.7445,"urls":["https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736712","description":"The net/url package does not set a limit on the number of query parameters in a query.\n\nWhile the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61726","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"urls":["https://go.dev/cl/736712","https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4341","https://access.redhat.com/errata/RHSA-2026:10096","https://access.redhat.com/errata/RHSA-2026:10104","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:11408","https://access.redhat.com/errata/RHSA-2026:11414","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12279","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13542","https://access.redhat.com/errata/RHSA-2026:13548","https://access.redhat.com/errata/RHSA-2026:13571","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:15984","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17446","https://access.redhat.com/errata/RHSA-2026:17460","https://access.redhat.com/errata/RHSA-2026:17463","https://access.redhat.com/errata/RHSA-2026:17468","https://access.redhat.com/errata/RHSA-2026:17595","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:18913","https://access.redhat.com/errata/RHSA-2026:19013","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26420","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:2681","https://access.redhat.com/errata/RHSA-2026:2706","https://access.redhat.com/errata/RHSA-2026:2708","https://access.redhat.com/errata/RHSA-2026:2709","https://access.redhat.com/errata/RHSA-2026:2754","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:2844","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:2914","https://access.redhat.com/errata/RHSA-2026:2920","https://access.redhat.com/errata/RHSA-2026:3035","https://access.redhat.com/errata/RHSA-2026:3040","https://access.redhat.com/errata/RHSA-2026:3089","https://access.redhat.com/errata/RHSA-2026:3092","https://access.redhat.com/errata/RHSA-2026:3184","https://access.redhat.com/errata/RHSA-2026:3186","https://access.redhat.com/errata/RHSA-2026:3187","https://access.redhat.com/errata/RHSA-2026:3188","https://access.redhat.com/errata/RHSA-2026:3192","https://access.redhat.com/errata/RHSA-2026:3193","https://access.redhat.com/errata/RHSA-2026:3291","https://access.redhat.com/errata/RHSA-2026:3296","https://access.redhat.com/errata/RHSA-2026:3297","https://access.redhat.com/errata/RHSA-2026:3298","https://access.redhat.com/errata/RHSA-2026:3336","https://access.redhat.com/errata/RHSA-2026:3337","https://access.redhat.com/errata/RHSA-2026:3340","https://access.redhat.com/errata/RHSA-2026:3341","https://access.redhat.com/errata/RHSA-2026:3343","https://access.redhat.com/errata/RHSA-2026:3391","https://access.redhat.com/errata/RHSA-2026:3416","https://access.redhat.com/errata/RHSA-2026:3427","https://access.redhat.com/errata/RHSA-2026:3459","https://access.redhat.com/errata/RHSA-2026:3468","https://access.redhat.com/errata/RHSA-2026:3469","https://access.redhat.com/errata/RHSA-2026:3470","https://access.redhat.com/errata/RHSA-2026:3471","https://access.redhat.com/errata/RHSA-2026:3472","https://access.redhat.com/errata/RHSA-2026:3473","https://access.redhat.com/errata/RHSA-2026:3489","https://access.redhat.com/errata/RHSA-2026:3506","https://access.redhat.com/errata/RHSA-2026:3556","https://access.redhat.com/errata/RHSA-2026:3559","https://access.redhat.com/errata/RHSA-2026:3668","https://access.redhat.com/errata/RHSA-2026:3669","https://access.redhat.com/errata/RHSA-2026:36873","https://access.redhat.com/errata/RHSA-2026:36882","https://access.redhat.com/errata/RHSA-2026:3699","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:3752","https://access.redhat.com/errata/RHSA-2026:3753","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3812","https://access.redhat.com/errata/RHSA-2026:3813","https://access.redhat.com/errata/RHSA-2026:3814","https://access.redhat.com/errata/RHSA-2026:3815","https://access.redhat.com/errata/RHSA-2026:3816","https://access.redhat.com/errata/RHSA-2026:3817","https://access.redhat.com/errata/RHSA-2026:3818","https://access.redhat.com/errata/RHSA-2026:3820","https://access.redhat.com/errata/RHSA-2026:3821","https://access.redhat.com/errata/RHSA-2026:3822","https://access.redhat.com/errata/RHSA-2026:3831","https://access.redhat.com/errata/RHSA-2026:3833","https://access.redhat.com/errata/RHSA-2026:3835","https://access.redhat.com/errata/RHSA-2026:3836","https://access.redhat.com/errata/RHSA-2026:3838","https://access.redhat.com/errata/RHSA-2026:3839","https://access.redhat.com/errata/RHSA-2026:3840","https://access.redhat.com/errata/RHSA-2026:3841","https://access.redhat.com/errata/RHSA-2026:3843","https://access.redhat.com/errata/RHSA-2026:3854","https://access.redhat.com/errata/RHSA-2026:3855","https://access.redhat.com/errata/RHSA-2026:3856","https://access.redhat.com/errata/RHSA-2026:3864","https://access.redhat.com/errata/RHSA-2026:3869","https://access.redhat.com/errata/RHSA-2026:3874","https://access.redhat.com/errata/RHSA-2026:3875","https://access.redhat.com/errata/RHSA-2026:3879","https://access.redhat.com/errata/RHSA-2026:3880","https://access.redhat.com/errata/RHSA-2026:3884","https://access.redhat.com/errata/RHSA-2026:3898","https://access.redhat.com/errata/RHSA-2026:3905","https://access.redhat.com/errata/RHSA-2026:3906","https://access.redhat.com/errata/RHSA-2026:3928","https://access.redhat.com/errata/RHSA-2026:3929","https://access.redhat.com/errata/RHSA-2026:3930","https://access.redhat.com/errata/RHSA-2026:3931","https://access.redhat.com/errata/RHSA-2026:3932","https://access.redhat.com/errata/RHSA-2026:3958","https://access.redhat.com/errata/RHSA-2026:3959","https://access.redhat.com/errata/RHSA-2026:3960","https://access.redhat.com/errata/RHSA-2026:3970","https://access.redhat.com/errata/RHSA-2026:3971","https://access.redhat.com/errata/RHSA-2026:3972","https://access.redhat.com/errata/RHSA-2026:3973","https://access.redhat.com/errata/RHSA-2026:3974","https://access.redhat.com/errata/RHSA-2026:3977","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:3985","https://access.redhat.com/errata/RHSA-2026:40924","https://access.redhat.com/errata/RHSA-2026:4164","https://access.redhat.com/errata/RHSA-2026:4166","https://access.redhat.com/errata/RHSA-2026:4170","https://access.redhat.com/errata/RHSA-2026:4174","https://access.redhat.com/errata/RHSA-2026:4177","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41941","https://access.redhat.com/errata/RHSA-2026:4211","https://access.redhat.com/errata/RHSA-2026:4220","https://access.redhat.com/errata/RHSA-2026:4256","https://access.redhat.com/errata/RHSA-2026:4264","https://access.redhat.com/errata/RHSA-2026:4267","https://access.redhat.com/errata/RHSA-2026:4270","https://access.redhat.com/errata/RHSA-2026:4276","https://access.redhat.com/errata/RHSA-2026:4434","https://access.redhat.com/errata/RHSA-2026:4435","https://access.redhat.com/errata/RHSA-2026:4460","https://access.redhat.com/errata/RHSA-2026:4466","https://access.redhat.com/errata/RHSA-2026:4467","https://access.redhat.com/errata/RHSA-2026:4498","https://access.redhat.com/errata/RHSA-2026:4500","https://access.redhat.com/errata/RHSA-2026:4510","https://access.redhat.com/errata/RHSA-2026:4511","https://access.redhat.com/errata/RHSA-2026:4672","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:4753","https://access.redhat.com/errata/RHSA-2026:4892","https://access.redhat.com/errata/RHSA-2026:4901","https://access.redhat.com/errata/RHSA-2026:4907","https://access.redhat.com/errata/RHSA-2026:4939","https://access.redhat.com/errata/RHSA-2026:4942","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:4952","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5022","https://access.redhat.com/errata/RHSA-2026:5030","https://access.redhat.com/errata/RHSA-2026:5031","https://access.redhat.com/errata/RHSA-2026:5076","https://access.redhat.com/errata/RHSA-2026:5077","https://access.redhat.com/errata/RHSA-2026:5078","https://access.redhat.com/errata/RHSA-2026:5079","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:5129","https://access.redhat.com/errata/RHSA-2026:5130","https://access.redhat.com/errata/RHSA-2026:5131","https://access.redhat.com/errata/RHSA-2026:5132","https://access.redhat.com/errata/RHSA-2026:5145","https://access.redhat.com/errata/RHSA-2026:5146","https://access.redhat.com/errata/RHSA-2026:5168","https://access.redhat.com/errata/RHSA-2026:5327","https://access.redhat.com/errata/RHSA-2026:5394","https://access.redhat.com/errata/RHSA-2026:5439","https://access.redhat.com/errata/RHSA-2026:5444","https://access.redhat.com/errata/RHSA-2026:5447","https://access.redhat.com/errata/RHSA-2026:5452","https://access.redhat.com/errata/RHSA-2026:5461","https://access.redhat.com/errata/RHSA-2026:5463","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5533","https://access.redhat.com/errata/RHSA-2026:5544","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:5636","https://access.redhat.com/errata/RHSA-2026:56366","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:5645","https://access.redhat.com/errata/RHSA-2026:5649","https://access.redhat.com/errata/RHSA-2026:5665","https://access.redhat.com/errata/RHSA-2026:57013","https://access.redhat.com/errata/RHSA-2026:5807","https://access.redhat.com/errata/RHSA-2026:5851","https://access.redhat.com/errata/RHSA-2026:5852","https://access.redhat.com/errata/RHSA-2026:5853","https://access.redhat.com/errata/RHSA-2026:5948","https://access.redhat.com/errata/RHSA-2026:5950","https://access.redhat.com/errata/RHSA-2026:5952","https://access.redhat.com/errata/RHSA-2026:5968","https://access.redhat.com/errata/RHSA-2026:6184","https://access.redhat.com/errata/RHSA-2026:6192","https://access.redhat.com/errata/RHSA-2026:6226","https://access.redhat.com/errata/RHSA-2026:6251","https://access.redhat.com/errata/RHSA-2026:6277","https://access.redhat.com/errata/RHSA-2026:6278","https://access.redhat.com/errata/RHSA-2026:6428","https://access.redhat.com/errata/RHSA-2026:6429","https://access.redhat.com/errata/RHSA-2026:6497","https://access.redhat.com/errata/RHSA-2026:6554","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:6567","https://access.redhat.com/errata/RHSA-2026:6568","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:7052","https://access.redhat.com/errata/RHSA-2026:7249","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7676","https://access.redhat.com/errata/RHSA-2026:7854","https://access.redhat.com/errata/RHSA-2026:7942","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8218","https://access.redhat.com/errata/RHSA-2026:8229","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8431","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9848","https://access.redhat.com/security/cve/CVE-2025-61726","https://bugzilla.redhat.com/show_bug.cgi?id=2434432","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61726","description":"The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.2015,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.  Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service.  CWE: CWE-476: NULL Pointer Dereference  Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted.  This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.2015,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.  Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service.  CWE: CWE-476: NULL Pointer Dereference  Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted.  This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.2015,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.  Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service.  CWE: CWE-476: NULL Pointer Dereference  Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted.  This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18798","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18798","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"risk":1.15275,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet.  Impact summary: Double free leads to heap corruption, which typically results in  termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable.  CWE: CWE-415: Double Free  Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time.  The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length.  FIPS impact: no The FIPS module is not affected, as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-18798","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"urls":["https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af","https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c","https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18798","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18798","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"risk":1.15275,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet.  Impact summary: Double free leads to heap corruption, which typically results in  termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable.  CWE: CWE-415: Double Free  Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time.  The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length.  FIPS impact: no The FIPS module is not affected, as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-18798","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"urls":["https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af","https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c","https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18798","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18798","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"risk":1.15275,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet.  Impact summary: Double free leads to heap corruption, which typically results in  termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable.  CWE: CWE-415: Double Free  Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time.  The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length.  FIPS impact: no The FIPS module is not affected, as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-18798","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-08","epss":0.01537,"percentile":0.74104}],"urls":["https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af","https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c","https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63073","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63073","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"risk":1.08946,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`.  Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender.  CWE: CWE-134 (Use of Externally-Controlled Format String)  Description: When validating a received CMP message, ossl_cmp_msg_check_update() converts the peer-supplied sender distinguished name with X509_NAME_oneline() and passes it directly as the format argument to ERR_raise_data(). Percent characters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches BIO_vsnprintf() as an attacker-controlled format string with no matching variadic arguments. This path is only reached when the caller configures an expected sender or pins a server certificate, which is the normal configuration for a CMP client validating server responses.  Since the attacker controls the format string but none of the variadic arguments, such specifiers as %s and %n dereference or write through unrelated stack contents and crash the client. The reliable consequence is a denial of service, when the response comes from a malicious or intercepted CMP endpoint. There is no controlled memory write, arbitrary-address read, or reliable path to remote code execution.  FIPS impact: no  No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-63073","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"urls":["https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca","https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29","https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21","https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63073","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63073","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"risk":1.08946,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`.  Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender.  CWE: CWE-134 (Use of Externally-Controlled Format String)  Description: When validating a received CMP message, ossl_cmp_msg_check_update() converts the peer-supplied sender distinguished name with X509_NAME_oneline() and passes it directly as the format argument to ERR_raise_data(). Percent characters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches BIO_vsnprintf() as an attacker-controlled format string with no matching variadic arguments. This path is only reached when the caller configures an expected sender or pins a server certificate, which is the normal configuration for a CMP client validating server responses.  Since the attacker controls the format string but none of the variadic arguments, such specifiers as %s and %n dereference or write through unrelated stack contents and crash the client. The reliable consequence is a denial of service, when the response comes from a malicious or intercepted CMP endpoint. There is no controlled memory write, arbitrary-address read, or reliable path to remote code execution.  FIPS impact: no  No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-63073","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"urls":["https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca","https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29","https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21","https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63073","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63073","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"risk":1.08946,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`.  Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender.  CWE: CWE-134 (Use of Externally-Controlled Format String)  Description: When validating a received CMP message, ossl_cmp_msg_check_update() converts the peer-supplied sender distinguished name with X509_NAME_oneline() and passes it directly as the format argument to ERR_raise_data(). Percent characters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches BIO_vsnprintf() as an attacker-controlled format string with no matching variadic arguments. This path is only reached when the caller configures an expected sender or pins a server certificate, which is the normal configuration for a CMP client validating server responses.  Since the attacker controls the format string but none of the variadic arguments, such specifiers as %s and %n dereference or write through unrelated stack contents and crash the client. The reliable consequence is a denial of service, when the response comes from a malicious or intercepted CMP endpoint. There is no controlled memory write, arbitrary-address read, or reliable path to remote code execution.  FIPS impact: no  No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-63073","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-08","epss":0.01159,"percentile":0.66134}],"urls":["https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca","https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29","https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21","https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6110","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-6110","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-6110","date":"2026-10-08","epss":0.20906,"percentile":0.97507}],"risk":1.0453000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6110","description":"In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred."},"relatedVulnerabilities":[{"id":"CVE-2019-6110","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-6110","date":"2026-10-08","epss":0.20906,"percentile":0.97507}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf","https://cvsweb.openbsd.org/src/usr.bin/ssh/progressmeter.c","https://cvsweb.openbsd.org/src/usr.bin/ssh/scp.c","https://security.gentoo.org/glsa/201903-16","https://security.netapp.com/advisory/ntap-20190213-0001/","https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt","https://www.exploit-db.com/exploits/46193/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6110","description":"In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4337","versionConstraint":"<1.24.13||>=1.25.0-0,<1.25.7||>=1.26.0-rc.1,<1.26.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4337","fix":{"state":"fixed","versions":["1.24.13","1.25.7","1.26.0-rc.3"],"available":[{"date":"2026-02-04","kind":"release","version":"1.24.13"},{"date":"2026-02-04","kind":"release","version":"1.25.7"},{"date":"2026-02-04","kind":"release","version":"1.26.0-rc.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"risk":0.8692500000000001,"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."},"relatedVulnerabilities":[{"id":"CVE-2025-68121","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217","https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","https://pkg.go.dev/vuln/GO-2026-4337"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68121","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14457","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14457","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"risk":0.76575,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted \"signature_algorithms_cert\" TLS extension.  Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible.  CWE: CWE-476: NULL Pointer Dereference  Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA).  When the private key is configured along with a matching certificate, the \"signature_algorithms_cert\" extension is handled reliably even without the fix, and peer clients or servers that don't support raw public keys may be able to complete a TLS connection by pinning or verifying the corresponding certificate or its public key.  Deployments that prefer to configure just a private key with no certificate need to upgrade to an updated release as noted below.  FIPS impact: no  No FIPS modules are affected by this issue, as the SSL protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-14457","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"urls":["https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76","https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1","https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f","https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-14457","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14457","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"risk":0.76575,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted \"signature_algorithms_cert\" TLS extension.  Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible.  CWE: CWE-476: NULL Pointer Dereference  Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA).  When the private key is configured along with a matching certificate, the \"signature_algorithms_cert\" extension is handled reliably even without the fix, and peer clients or servers that don't support raw public keys may be able to complete a TLS connection by pinning or verifying the corresponding certificate or its public key.  Deployments that prefer to configure just a private key with no certificate need to upgrade to an updated release as noted below.  FIPS impact: no  No FIPS modules are affected by this issue, as the SSL protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-14457","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"urls":["https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76","https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1","https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f","https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14457","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14457","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"risk":0.76575,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted \"signature_algorithms_cert\" TLS extension.  Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible.  CWE: CWE-476: NULL Pointer Dereference  Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA).  When the private key is configured along with a matching certificate, the \"signature_algorithms_cert\" extension is handled reliably even without the fix, and peer clients or servers that don't support raw public keys may be able to complete a TLS connection by pinning or verifying the corresponding certificate or its public key.  Deployments that prefer to configure just a private key with no certificate need to upgrade to an updated release as noted below.  FIPS impact: no  No FIPS modules are affected by this issue, as the SSL protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-14457","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-08","epss":0.01021,"percentile":0.62327}],"urls":["https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76","https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1","https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f","https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.6869999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.  Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure.  The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation.  FIPS impact: no  As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.6869999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.  Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure.  The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation.  FIPS impact: no  As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.6869999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.  Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure.  The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation.  FIPS impact: no  As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"< 2.41-12+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"fixed","versions":["2.41-12+deb13u4"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"2.41-12+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"< 2.41-12+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"fixed","versions":["2.41-12+deb13u4"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"2.41-12+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15778","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2020-15778","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15778","date":"2026-10-08","epss":0.12996,"percentile":0.96239}],"risk":0.6498,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15778","description":"scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of \"anomalous argument transfers\" because that could \"stand a great chance of breaking existing workflows.\""},"relatedVulnerabilities":[{"id":"CVE-2020-15778","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.6},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15778","date":"2026-10-08","epss":0.12996,"percentile":0.96239}],"urls":["https://access.redhat.com/errata/RHSA-2024:3166","https://github.com/cpandya2909/CVE-2020-15778/","https://news.ycombinator.com/item?id=25005567","https://security.gentoo.org/glsa/202212-06","https://security.netapp.com/advisory/ntap-20200731-0007/","https://www.openssh.com/security.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15778","description":"scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of \"anomalous argument transfers\" because that could \"stand a great chance of breaking existing workflows.\""}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f5wc-c3c7-36mc","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-f5wc-c3c7-36mc","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39832","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39832","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39832","date":"2026-10-08","epss":0.00716,"percentile":0.52306}],"risk":0.64798,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39832","https://go.dev/cl/778642","https://go.dev/issue/79435","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5006","https://access.redhat.com/security/cve/CVE-2026-39832","https://bugzilla.redhat.com/show_bug.cgi?id=2480685","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f5wc-c3c7-36mc","description":"golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys"},"relatedVulnerabilities":[{"id":"CVE-2026-39832","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.7,"impactScore":5.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39832","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39832","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39832","date":"2026-10-08","epss":0.00716,"percentile":0.52306}],"urls":["https://go.dev/cl/778640","https://go.dev/cl/778641","https://go.dev/issue/79435","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5006","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59579","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-39832","https://bugzilla.redhat.com/show_bug.cgi?id=2480685","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39832","description":"When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4601","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4601","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"risk":0.6255000000000001,"urls":["https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/752180","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-25679","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"urls":["https://go.dev/cl/752180","https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4601","https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10125","https://access.redhat.com/errata/RHSA-2026:10133","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10158","https://access.redhat.com/errata/RHSA-2026:10169","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:10701","https://access.redhat.com/errata/RHSA-2026:10712","https://access.redhat.com/errata/RHSA-2026:10929","https://access.redhat.com/errata/RHSA-2026:11217","https://access.redhat.com/errata/RHSA-2026:11375","https://access.redhat.com/errata/RHSA-2026:11412","https://access.redhat.com/errata/RHSA-2026:11413","https://access.redhat.com/errata/RHSA-2026:11686","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:11800","https://access.redhat.com/errata/RHSA-2026:11856","https://access.redhat.com/errata/RHSA-2026:11916","https://access.redhat.com/errata/RHSA-2026:11996","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13642","https://access.redhat.com/errata/RHSA-2026:13643","https://access.redhat.com/errata/RHSA-2026:13671","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:19017","https://access.redhat.com/errata/RHSA-2026:19022","https://access.redhat.com/errata/RHSA-2026:19026","https://access.redhat.com/errata/RHSA-2026:19027","https://access.redhat.com/errata/RHSA-2026:19031","https://access.redhat.com/errata/RHSA-2026:19032","https://access.redhat.com/errata/RHSA-2026:19049","https://access.redhat.com/errata/RHSA-2026:19055","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19128","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19181","https://access.redhat.com/errata/RHSA-2026:19184","https://access.redhat.com/errata/RHSA-2026:19185","https://access.redhat.com/errata/RHSA-2026:19207","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19475","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:20088","https://access.redhat.com/errata/RHSA-2026:20581","https://access.redhat.com/errata/RHSA-2026:20582","https://access.redhat.com/errata/RHSA-2026:20584","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:21696","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22733","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24386","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:25043","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26445","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28893","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:52389","https://access.redhat.com/errata/RHSA-2026:52390","https://access.redhat.com/errata/RHSA-2026:52391","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:5941","https://access.redhat.com/errata/RHSA-2026:5942","https://access.redhat.com/errata/RHSA-2026:5943","https://access.redhat.com/errata/RHSA-2026:5944","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:6341","https://access.redhat.com/errata/RHSA-2026:6344","https://access.redhat.com/errata/RHSA-2026:6382","https://access.redhat.com/errata/RHSA-2026:6383","https://access.redhat.com/errata/RHSA-2026:6388","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:6720","https://access.redhat.com/errata/RHSA-2026:6802","https://access.redhat.com/errata/RHSA-2026:6949","https://access.redhat.com/errata/RHSA-2026:7005","https://access.redhat.com/errata/RHSA-2026:7009","https://access.redhat.com/errata/RHSA-2026:7011","https://access.redhat.com/errata/RHSA-2026:7259","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7315","https://access.redhat.com/errata/RHSA-2026:7328","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7665","https://access.redhat.com/errata/RHSA-2026:7669","https://access.redhat.com/errata/RHSA-2026:7674","https://access.redhat.com/errata/RHSA-2026:7833","https://access.redhat.com/errata/RHSA-2026:7834","https://access.redhat.com/errata/RHSA-2026:7876","https://access.redhat.com/errata/RHSA-2026:7877","https://access.redhat.com/errata/RHSA-2026:7878","https://access.redhat.com/errata/RHSA-2026:7879","https://access.redhat.com/errata/RHSA-2026:7883","https://access.redhat.com/errata/RHSA-2026:7992","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8314","https://access.redhat.com/errata/RHSA-2026:8322","https://access.redhat.com/errata/RHSA-2026:8324","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8434","https://access.redhat.com/errata/RHSA-2026:8456","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:8484","https://access.redhat.com/errata/RHSA-2026:8490","https://access.redhat.com/errata/RHSA-2026:8491","https://access.redhat.com/errata/RHSA-2026:8493","https://access.redhat.com/errata/RHSA-2026:8840","https://access.redhat.com/errata/RHSA-2026:8841","https://access.redhat.com/errata/RHSA-2026:8842","https://access.redhat.com/errata/RHSA-2026:8845","https://access.redhat.com/errata/RHSA-2026:8847","https://access.redhat.com/errata/RHSA-2026:8848","https://access.redhat.com/errata/RHSA-2026:8849","https://access.redhat.com/errata/RHSA-2026:8851","https://access.redhat.com/errata/RHSA-2026:8852","https://access.redhat.com/errata/RHSA-2026:8853","https://access.redhat.com/errata/RHSA-2026:8855","https://access.redhat.com/errata/RHSA-2026:8856","https://access.redhat.com/errata/RHSA-2026:8860","https://access.redhat.com/errata/RHSA-2026:8877","https://access.redhat.com/errata/RHSA-2026:8878","https://access.redhat.com/errata/RHSA-2026:8879","https://access.redhat.com/errata/RHSA-2026:8881","https://access.redhat.com/errata/RHSA-2026:8882","https://access.redhat.com/errata/RHSA-2026:8930","https://access.redhat.com/errata/RHSA-2026:8931","https://access.redhat.com/errata/RHSA-2026:8949","https://access.redhat.com/errata/RHSA-2026:9043","https://access.redhat.com/errata/RHSA-2026:9044","https://access.redhat.com/errata/RHSA-2026:9052","https://access.redhat.com/errata/RHSA-2026:9090","https://access.redhat.com/errata/RHSA-2026:9093","https://access.redhat.com/errata/RHSA-2026:9094","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/errata/RHSA-2026:9434","https://access.redhat.com/errata/RHSA-2026:9435","https://access.redhat.com/errata/RHSA-2026:9436","https://access.redhat.com/errata/RHSA-2026:9439","https://access.redhat.com/errata/RHSA-2026:9440","https://access.redhat.com/errata/RHSA-2026:9448","https://access.redhat.com/errata/RHSA-2026:9453","https://access.redhat.com/errata/RHSA-2026:9461","https://access.redhat.com/errata/RHSA-2026:9695","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/errata/RHSA-2026:9872","https://access.redhat.com/security/cve/CVE-2026-25679","https://bugzilla.redhat.com/show_bug.cgi?id=2445356","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25679","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4981","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4981","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"risk":0.60975,"urls":["https://go.dev/cl/767860","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78803","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."},"relatedVulnerabilities":[{"id":"CVE-2026-33811","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"urls":["https://go.dev/cl/767860","https://go.dev/issue/78803","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4981","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:35995","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36617","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36776","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:39266","https://access.redhat.com/errata/RHSA-2026:39272","https://access.redhat.com/errata/RHSA-2026:39319","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54556","https://access.redhat.com/errata/RHSA-2026:54584","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56790","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60302","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61313","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/security/cve/CVE-2026-33811","https://bugzilla.redhat.com/show_bug.cgi?id=2467822","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33811","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."}]},{"artifact":{"id":"5e92736840e45ef8","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.2-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.2-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=expat","type":"deb","version":"2.8.2-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66046","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"expat","version":"2.8.2-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66046","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"risk":0.60102,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."},"relatedVulnerabilities":[{"id":"CVE-2026-66046","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"urls":["https://github.com/libexpat/libexpat/pull/1321","https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4977","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4977","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"risk":0.5984999999999999,"urls":["https://go.dev/cl/771520","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78987","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."},"relatedVulnerabilities":[{"id":"CVE-2026-42499","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"urls":["https://go.dev/cl/771520","https://go.dev/issue/78987","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4977","https://access.redhat.com/errata/RHSA-2026:17713","https://access.redhat.com/errata/RHSA-2026:17714","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:63163","https://access.redhat.com/errata/RHSA-2026:63332","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:64818","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67148","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-42499","https://bugzilla.redhat.com/show_bug.cgi?id=2467809","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42499","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5cgq-3rg8-m6cv","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-5cgq-3rg8-m6cv","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42508","date":"2026-10-08","epss":0.00654,"percentile":0.49763}],"risk":0.59187,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-42508","https://go.dev/cl/781220","https://go.dev/issue/79568","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5021","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/security/cve/CVE-2026-42508","https://bugzilla.redhat.com/show_bug.cgi?id=2480688","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40138","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41064","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:40945"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5cgq-3rg8-m6cv","description":"golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status"},"relatedVulnerabilities":[{"id":"CVE-2026-42508","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42508","date":"2026-10-08","epss":0.00654,"percentile":0.49763}],"urls":["https://go.dev/cl/781220","https://go.dev/issue/79568","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5021","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41064","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-42508","https://bugzilla.redhat.com/show_bug.cgi?id=2480688","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42508","description":"Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4986","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4986","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"risk":0.588,"urls":["https://go.dev/cl/759940","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78566","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-39820","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"urls":["https://go.dev/cl/759940","https://go.dev/issue/78566","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4986","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54883","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57401","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-39820","https://bugzilla.redhat.com/show_bug.cgi?id=2467820","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39820","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."}]},{"artifact":{"id":"efad814c9c04e9fa","cpes":["cpe:2.3:a:golang:networking:v0.38.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.38.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.38.0","type":"go-module","version":"v0.38.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.53.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4918","versionConstraint":"<0.53.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.38.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4918","fix":{"state":"fixed","versions":["0.53.0"],"available":[{"date":"2026-04-09","kind":"release","version":"0.53.0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"risk":0.58575,"urls":["https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/761581","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."},"relatedVulnerabilities":[{"id":"CVE-2026-33814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"urls":["https://go.dev/cl/761581","https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4918","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57367","https://access.redhat.com/errata/RHSA-2026:57408","https://access.redhat.com/errata/RHSA-2026:57545","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60441","https://access.redhat.com/errata/RHSA-2026:60442","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60447","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60478","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:60668","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62410","https://access.redhat.com/errata/RHSA-2026:62550","https://access.redhat.com/errata/RHSA-2026:62551","https://access.redhat.com/errata/RHSA-2026:63046","https://access.redhat.com/errata/RHSA-2026:63047","https://access.redhat.com/errata/RHSA-2026:63048","https://access.redhat.com/errata/RHSA-2026:63050","https://access.redhat.com/errata/RHSA-2026:63091","https://access.redhat.com/errata/RHSA-2026:63096","https://access.redhat.com/errata/RHSA-2026:63097","https://access.redhat.com/errata/RHSA-2026:63103","https://access.redhat.com/errata/RHSA-2026:63104","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:63637","https://access.redhat.com/errata/RHSA-2026:63639","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/security/cve/CVE-2026-33814","https://bugzilla.redhat.com/show_bug.cgi?id=2467815","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33814","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4918","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4918","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"risk":0.58575,"urls":["https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/761581","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."},"relatedVulnerabilities":[{"id":"CVE-2026-33814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"urls":["https://go.dev/cl/761581","https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4918","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57367","https://access.redhat.com/errata/RHSA-2026:57408","https://access.redhat.com/errata/RHSA-2026:57545","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60441","https://access.redhat.com/errata/RHSA-2026:60442","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60447","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60478","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:60668","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62410","https://access.redhat.com/errata/RHSA-2026:62550","https://access.redhat.com/errata/RHSA-2026:62551","https://access.redhat.com/errata/RHSA-2026:63046","https://access.redhat.com/errata/RHSA-2026:63047","https://access.redhat.com/errata/RHSA-2026:63048","https://access.redhat.com/errata/RHSA-2026:63050","https://access.redhat.com/errata/RHSA-2026:63091","https://access.redhat.com/errata/RHSA-2026:63096","https://access.redhat.com/errata/RHSA-2026:63097","https://access.redhat.com/errata/RHSA-2026:63103","https://access.redhat.com/errata/RHSA-2026:63104","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:63637","https://access.redhat.com/errata/RHSA-2026:63639","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/security/cve/CVE-2026-33814","https://bugzilla.redhat.com/show_bug.cgi?id=2467815","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33814","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63075","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63075","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"risk":0.5835,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection.  Impact summary: A remote peer that can complete a QUIC handshake can cause connection-scoped memory growth which may lead to Denial of Service through memory exhaustion, especially with sustained traffic or many concurrent QUIC connections.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: When the OpenSSL QUIC stack sends an ACK-only packet, there is no requirement by the QUIC protocol that the peer will acknowledge that ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL implementation stores the metadata about the ACK frames regardless. In and of itself that's ok, but if a malicious peer establishes a connection, and then drives the connection such that ACK-only packets are forced from the  OpenSSL implementation peer (i.e., by sending numerous PING frames), and then withholding any subsequent acks for ack-eliciting data, like legitimate data, said malicious peer can force inappropriate memory growth on the OpenSSL peer, potentially leading to a Denial of Service.  The fix is to ensure that we account for the transmission of the ACK-only packet in the packet histories high and low watermark without actually storing the ACK-only packet metadata itself.  FIPS impact: no The OpenSSL FIPS module is not affected as the QUIC code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-63075","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"urls":["https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63075","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63075","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"risk":0.5835,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection.  Impact summary: A remote peer that can complete a QUIC handshake can cause connection-scoped memory growth which may lead to Denial of Service through memory exhaustion, especially with sustained traffic or many concurrent QUIC connections.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: When the OpenSSL QUIC stack sends an ACK-only packet, there is no requirement by the QUIC protocol that the peer will acknowledge that ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL implementation stores the metadata about the ACK frames regardless. In and of itself that's ok, but if a malicious peer establishes a connection, and then drives the connection such that ACK-only packets are forced from the  OpenSSL implementation peer (i.e., by sending numerous PING frames), and then withholding any subsequent acks for ack-eliciting data, like legitimate data, said malicious peer can force inappropriate memory growth on the OpenSSL peer, potentially leading to a Denial of Service.  The fix is to ensure that we account for the transmission of the ACK-only packet in the packet histories high and low watermark without actually storing the ACK-only packet metadata itself.  FIPS impact: no The OpenSSL FIPS module is not affected as the QUIC code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-63075","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"urls":["https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63075","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63075","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"risk":0.5835,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection.  Impact summary: A remote peer that can complete a QUIC handshake can cause connection-scoped memory growth which may lead to Denial of Service through memory exhaustion, especially with sustained traffic or many concurrent QUIC connections.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: When the OpenSSL QUIC stack sends an ACK-only packet, there is no requirement by the QUIC protocol that the peer will acknowledge that ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL implementation stores the metadata about the ACK frames regardless. In and of itself that's ok, but if a malicious peer establishes a connection, and then drives the connection such that ACK-only packets are forced from the  OpenSSL implementation peer (i.e., by sending numerous PING frames), and then withholding any subsequent acks for ack-eliciting data, like legitimate data, said malicious peer can force inappropriate memory growth on the OpenSSL peer, potentially leading to a Denial of Service.  The fix is to ensure that we account for the transmission of the ACK-only packet in the packet histories high and low watermark without actually storing the ACK-only packet metadata itself.  FIPS impact: no The OpenSSL FIPS module is not affected as the QUIC code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-63075","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-08","epss":0.00778,"percentile":0.5448}],"urls":["https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rm3j-f69w-wqmq","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-rm3j-f69w-wqmq","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39834","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39834","date":"2026-10-08","epss":0.00637,"percentile":0.48909}],"risk":0.576485,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39834","https://go.dev/cl/781663","https://go.dev/issue/79567","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5020"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rm3j-f69w-wqmq","description":"golang.org/x/crypto vulnerable to infinite loop on large channel writes"},"relatedVulnerabilities":[{"id":"CVE-2026-39834","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39834","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39834","date":"2026-10-08","epss":0.00637,"percentile":0.48909}],"urls":["https://go.dev/cl/781663","https://go.dev/issue/79567","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5020"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39834","description":"When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation."}]},{"artifact":{"id":"99d64a21b6e327fd","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=libssh2","type":"deb","version":"1.11.1-1+deb13u1","language":"","licenses":["BSD3","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libssh2-1t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66033","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"libssh2","version":"1.11.1-1+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66033","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66033","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66033","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66033","date":"2026-10-08","epss":0.00695,"percentile":0.51501}],"risk":0.56295,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66033","description":"libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs."},"relatedVulnerabilities":[{"id":"CVE-2026-66033","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66033","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66033","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66033","date":"2026-10-08","epss":0.00695,"percentile":0.51501}],"urls":["https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6","https://github.com/libssh2/libssh2/pull/2401","https://www.vulncheck.com/advisories/libssh2-integer-underflow-dos-via-aes-gcm-cipher-negotiation"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66033","description":"libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vgwf-h737-ff37","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-vgwf-h737-ff37","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39830","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39830","cwe":"CWE-772","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39830","date":"2026-10-08","epss":0.00621,"percentile":0.48178}],"risk":0.5620050000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39830","https://go.dev/cl/781640","https://go.dev/cl/781664","https://go.dev/issue/79564","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5017","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/security/cve/CVE-2026-39830","https://bugzilla.redhat.com/show_bug.cgi?id=2480684","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39830.json","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65964","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vgwf-h737-ff37","description":"golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses"},"relatedVulnerabilities":[{"id":"CVE-2026-39830","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39830","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39830","cwe":"CWE-772","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39830","date":"2026-10-08","epss":0.00621,"percentile":0.48178}],"urls":["https://go.dev/cl/781640","https://go.dev/cl/781664","https://go.dev/issue/79564","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5017","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65964","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-39830","https://bugzilla.redhat.com/show_bug.cgi?id=2480684","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39830.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39830","description":"A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9079","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"risk":0.54896,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them."},"relatedVulnerabilities":[{"id":"CVE-2026-9079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9079","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"risk":0.54896,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them."},"relatedVulnerabilities":[{"id":"CVE-2026-9079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9079","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"risk":0.54896,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them."},"relatedVulnerabilities":[{"id":"CVE-2026-9079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14456","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14456","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"risk":0.5467500000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.  Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store the per-channel state to grow without any limits, potentially making the QUIC listener unavailable and causing Denial of Service.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The function that handles inbound QUIC packets uses Connection-Id from the packet header to find an existing connection (QUIC channel). If no existing connection is found and the packet type is INITIAL, the function treats the packet as a new connection. It allocates a new channel object and inserts it into a queue where it waits to be accepted by the local application with SSL_accept(3ossl). The memory occupied by these initial channel objects may grow without bounds if the application is not able to call SSL_accept() frequently enough to serve these inbound connection requests.  The issue is present since OpenSSL 3.5 when the QUIC server implementation was added.  The fix introduces a limit for pending connections. The default limit is set to 256 pending connections (waiting to be accepted by the local application). Applications may change the default by calling SSL_set_value_uint(3ossl).  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-14456","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"urls":["https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9","https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b","https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139","https://openssl-library.org/news/secadv/20260813.txt","http://www.openwall.com/lists/oss-security/2026/08/13/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-14456","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14456","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"risk":0.5467500000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.  Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store the per-channel state to grow without any limits, potentially making the QUIC listener unavailable and causing Denial of Service.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The function that handles inbound QUIC packets uses Connection-Id from the packet header to find an existing connection (QUIC channel). If no existing connection is found and the packet type is INITIAL, the function treats the packet as a new connection. It allocates a new channel object and inserts it into a queue where it waits to be accepted by the local application with SSL_accept(3ossl). The memory occupied by these initial channel objects may grow without bounds if the application is not able to call SSL_accept() frequently enough to serve these inbound connection requests.  The issue is present since OpenSSL 3.5 when the QUIC server implementation was added.  The fix introduces a limit for pending connections. The default limit is set to 256 pending connections (waiting to be accepted by the local application). Applications may change the default by calling SSL_set_value_uint(3ossl).  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-14456","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"urls":["https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9","https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b","https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139","https://openssl-library.org/news/secadv/20260813.txt","http://www.openwall.com/lists/oss-security/2026/08/13/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14456","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14456","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"risk":0.5467500000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.  Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store the per-channel state to grow without any limits, potentially making the QUIC listener unavailable and causing Denial of Service.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The function that handles inbound QUIC packets uses Connection-Id from the packet header to find an existing connection (QUIC channel). If no existing connection is found and the packet type is INITIAL, the function treats the packet as a new connection. It allocates a new channel object and inserts it into a queue where it waits to be accepted by the local application with SSL_accept(3ossl). The memory occupied by these initial channel objects may grow without bounds if the application is not able to call SSL_accept() frequently enough to serve these inbound connection requests.  The issue is present since OpenSSL 3.5 when the QUIC server implementation was added.  The fix introduces a limit for pending connections. The default limit is set to 256 pending connections (waiting to be accepted by the local application). Applications may change the default by calling SSL_set_value_uint(3ossl).  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-14456","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-08","epss":0.00729,"percentile":0.52813}],"urls":["https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9","https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b","https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139","https://openssl-library.org/news/secadv/20260813.txt","http://www.openwall.com/lists/oss-security/2026/08/13/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"efad814c9c04e9fa","cpes":["cpe:2.3:a:golang:networking:v0.38.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.38.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.38.0","type":"go-module","version":"v0.38.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.38.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x527-x647-q7gg","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-x527-x647-q7gg","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","metrics":{"baseScore":10,"impactScore":6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46595","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-46595","cwe":"CWE-303","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46595","date":"2026-10-08","epss":0.00503,"percentile":0.41132}],"risk":0.47785,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-45337","https://nvd.nist.gov/vuln/detail/CVE-2026-46595","https://go.dev/cl/781642","https://go.dev/issue/79570","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5023","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/security/cve/CVE-2026-46595","https://bugzilla.redhat.com/show_bug.cgi?id=2480689","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:40945"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x527-x647-q7gg","description":"golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement"},"relatedVulnerabilities":[{"id":"CVE-2026-46595","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":5.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","metrics":{"baseScore":10,"impactScore":6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46595","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-46595","cwe":"CWE-303","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46595","date":"2026-10-08","epss":0.00503,"percentile":0.41132}],"urls":["https://go.dev/cl/781642","https://go.dev/issue/79570","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5023","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59558","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/security/cve/CVE-2026-46595","https://bugzilla.redhat.com/show_bug.cgi?id=2480689","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46595","description":"Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"efad814c9c04e9fa","cpes":["cpe:2.3:a:golang:networking:v0.38.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.38.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.38.0","type":"go-module","version":"v0.38.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.56.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5942","versionConstraint":"<0.56.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.38.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5942","fix":{"state":"fixed","versions":["0.56.0"],"available":[{"date":"2026-06-09","kind":"release","version":"0.56.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"risk":0.47250000000000003,"urls":["https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/786345","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-46600","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"urls":["https://go.dev/cl/786345","https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5942"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46600","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.43.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4116","versionConstraint":"<0.43.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4116","fix":{"state":"fixed","versions":["0.43.0"],"available":[{"date":"2025-10-08","kind":"release","version":"0.43.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47913","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47913","date":"2026-10-08","epss":0.00623,"percentile":0.48255}],"risk":0.46725000000000005,"urls":["https://go.dev/issue/75178","https://github.com/advisories/GHSA-56w8-48fp-6mgv"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/700295","description":"SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process."},"relatedVulnerabilities":[{"id":"CVE-2025-47913","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47913","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47913","date":"2026-10-08","epss":0.00623,"percentile":0.48255}],"urls":["https://github.com/advisories/GHSA-56w8-48fp-6mgv","https://go.dev/cl/700295","https://go.dev/issue/75178","https://pkg.go.dev/vuln/GO-2025-4116"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47913","description":"SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w879-237q-wc7r","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-w879-237q-wc7r","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39829","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39829","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39829","date":"2026-10-08","epss":0.00623,"percentile":0.48242}],"risk":0.46725000000000005,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39829","https://go.dev/cl/781641","https://go.dev/cl/781661","https://go.dev/issue/79565","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5018","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/security/cve/CVE-2026-39829","https://bugzilla.redhat.com/show_bug.cgi?id=2480681","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39829.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40119","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41055"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w879-237q-wc7r","description":"golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-39829","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39829","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39829","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39829","date":"2026-10-08","epss":0.00623,"percentile":0.48242}],"urls":["https://go.dev/cl/781641","https://go.dev/cl/781661","https://go.dev/issue/79565","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5018","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47949","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:48693","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:54432","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65964","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-39829","https://bugzilla.redhat.com/show_bug.cgi?id=2480681","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39829.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39829","description":"The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.46649999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.  Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service.  CWE: CWE-405: Asymmetric Resource Consumption (Amplification)  Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up.  Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network.  An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity.  FIPS impact: no  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.  OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.  Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr  This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell.  -- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt Caswell"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.46649999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.  Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service.  CWE: CWE-405: Asymmetric Resource Consumption (Amplification)  Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up.  Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network.  An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity.  FIPS impact: no  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.  OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.  Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr  This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell.  -- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt Caswell"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.46649999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.  Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service.  CWE: CWE-405: Asymmetric Resource Consumption (Amplification)  Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up.  Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network.  An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity.  FIPS impact: no  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.  OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.  Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr  This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell.  -- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt Caswell"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4870","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4870","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"risk":0.46575,"urls":["https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763767","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.\n\nThis only affects TLS 1.3."},"relatedVulnerabilities":[{"id":"CVE-2026-32283","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"urls":["https://go.dev/cl/763767","https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4870","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11704","https://access.redhat.com/errata/RHSA-2026:11711","https://access.redhat.com/errata/RHSA-2026:11712","https://access.redhat.com/errata/RHSA-2026:11863","https://access.redhat.com/errata/RHSA-2026:11881","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17075","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19134","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19136","https://access.redhat.com/errata/RHSA-2026:19137","https://access.redhat.com/errata/RHSA-2026:19139","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19156","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19351","https://access.redhat.com/errata/RHSA-2026:19352","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19369","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55898","https://access.redhat.com/errata/RHSA-2026:55900","https://access.redhat.com/errata/RHSA-2026:55901","https://access.redhat.com/errata/RHSA-2026:55902","https://access.redhat.com/errata/RHSA-2026:55903","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:57802","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65343","https://access.redhat.com/errata/RHSA-2026:65514","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66084","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:66523","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/security/cve/CVE-2026-32283","https://bugzilla.redhat.com/show_bug.cgi?id=2456338","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32283","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4971","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4971","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"risk":0.46499999999999997,"urls":["https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://go.dev/cl/775320"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79006","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."},"relatedVulnerabilities":[{"id":"CVE-2026-39836","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"urls":["https://go.dev/cl/775320","https://go.dev/issue/79006","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4971"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39836","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4h4-gmj2-qvw2","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-q4h4-gmj2-qvw2","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46597","cwe":"CWE-704","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-46597","date":"2026-10-08","epss":0.0062,"percentile":0.48082}],"risk":0.46499999999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-46597","https://go.dev/cl/781620","https://go.dev/issue/79561","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5013"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4h4-gmj2-qvw2","description":"golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic"},"relatedVulnerabilities":[{"id":"CVE-2026-46597","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46597","cwe":"CWE-704","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-46597","date":"2026-10-08","epss":0.0062,"percentile":0.48082}],"urls":["https://go.dev/cl/781620","https://go.dev/issue/79561","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5013"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46597","description":"An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-60000","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"risk":0.4635,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."},"relatedVulnerabilities":[{"id":"CVE-2026-60000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-08","epss":0.00618,"percentile":0.47997}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4947","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4947","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"risk":0.46125000000000005,"urls":["https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758320","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."},"relatedVulnerabilities":[{"id":"CVE-2026-32280","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"urls":["https://go.dev/cl/758320","https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4947","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16476","https://access.redhat.com/errata/RHSA-2026:16477","https://access.redhat.com/errata/RHSA-2026:16505","https://access.redhat.com/errata/RHSA-2026:16508","https://access.redhat.com/errata/RHSA-2026:16532","https://access.redhat.com/errata/RHSA-2026:16534","https://access.redhat.com/errata/RHSA-2026:16535","https://access.redhat.com/errata/RHSA-2026:16537","https://access.redhat.com/errata/RHSA-2026:16542","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21338","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:22130","https://access.redhat.com/errata/RHSA-2026:22141","https://access.redhat.com/errata/RHSA-2026:22258","https://access.redhat.com/errata/RHSA-2026:22260","https://access.redhat.com/errata/RHSA-2026:22268","https://access.redhat.com/errata/RHSA-2026:22309","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22415","https://access.redhat.com/errata/RHSA-2026:22422","https://access.redhat.com/errata/RHSA-2026:22465","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22840","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22958","https://access.redhat.com/errata/RHSA-2026:22959","https://access.redhat.com/errata/RHSA-2026:22960","https://access.redhat.com/errata/RHSA-2026:22961","https://access.redhat.com/errata/RHSA-2026:22962","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23244","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24359","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24478","https://access.redhat.com/errata/RHSA-2026:24716","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:28196","https://access.redhat.com/errata/RHSA-2026:28198","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:39894","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49526","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49838","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:59834","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61685","https://access.redhat.com/errata/RHSA-2026:61906","https://access.redhat.com/errata/RHSA-2026:61907","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/security/cve/CVE-2026-32280","https://bugzilla.redhat.com/show_bug.cgi?id=2456339","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32280","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"risk":0.45675000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"risk":0.45675000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"risk":0.45675000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"risk":0.45675000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.  fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.  Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8376","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"risk":0.45214,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."},"relatedVulnerabilities":[{"id":"CVE-2026-8376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8376","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"risk":0.45214,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."},"relatedVulnerabilities":[{"id":"CVE-2026-8376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8376","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"risk":0.45214,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."},"relatedVulnerabilities":[{"id":"CVE-2026-8376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8376","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"risk":0.45214,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.  Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.  A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."},"relatedVulnerabilities":[{"id":"CVE-2026-8376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5037","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5037","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"risk":0.4432500000000001,"urls":["https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/783621","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname.\n\nWith a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."},"relatedVulnerabilities":[{"id":"CVE-2026-27145","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"urls":["https://go.dev/cl/783621","https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5037","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:29980","https://access.redhat.com/errata/RHSA-2026:29981","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46394","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49705","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:49729","https://access.redhat.com/errata/RHSA-2026:49744","https://access.redhat.com/errata/RHSA-2026:49765","https://access.redhat.com/errata/RHSA-2026:49770","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:52946","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53416","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54427","https://access.redhat.com/errata/RHSA-2026:54432","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55899","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59556","https://access.redhat.com/errata/RHSA-2026:59557","https://access.redhat.com/errata/RHSA-2026:59558","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:59579","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60386","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60388","https://access.redhat.com/errata/RHSA-2026:60390","https://access.redhat.com/errata/RHSA-2026:60391","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:63016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68335","https://access.redhat.com/security/cve/CVE-2026-27145","https://bugzilla.redhat.com/show_bug.cgi?id=2484207","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27145","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-89gr-r52h-f8rx","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-89gr-r52h-f8rx","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39831","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39831","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"risk":0.440735,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39831","https://go.dev/cl/781662","https://go.dev/issue/79566","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5019"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-89gr-r52h-f8rx","description":"golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed"},"relatedVulnerabilities":[{"id":"CVE-2026-39831","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39831","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39831","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"urls":["https://go.dev/cl/781662","https://go.dev/issue/79566","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5019"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39831","description":"The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a \"no-touch-required\" extension in Permissions.Extensions from PublicKeyCallback."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jppx-rxg9-jmrx","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-jppx-rxg9-jmrx","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39833","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39833","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"risk":0.440735,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39833","https://go.dev/cl/778640","https://go.dev/cl/778641","https://go.dev/issue/79436","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5005"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jppx-rxg9-jmrx","description":"golang.org/x/crypto doesn't enforce invoking key constraints"},"relatedVulnerabilities":[{"id":"CVE-2026-39833","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39833","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39833","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"urls":["https://go.dev/cl/778642","https://go.dev/issue/79436","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5005"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39833","description":"The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested."}]},{"artifact":{"id":"5e92736840e45ef8","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.2-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.2-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=expat","type":"deb","version":"2.8.2-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"expat","version":"2.8.2-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.430965,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-2768","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2007-2768","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-2768","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2768","date":"2026-10-08","epss":0.08615,"percentile":0.94971}],"risk":0.4307500000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-2768","description":"OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243."},"relatedVulnerabilities":[{"id":"CVE-2007-2768","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-2768","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2768","date":"2026-10-08","epss":0.08615,"percentile":0.94971}],"urls":["http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0635.html","http://www.osvdb.org/34601","https://security.netapp.com/advisory/ntap-20191107-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-2768","description":"OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4342","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4342","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"risk":0.430675,"urls":["https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736713","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."},"relatedVulnerabilities":[{"id":"CVE-2025-61728","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"urls":["https://go.dev/cl/736713","https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4342","http://www.openwall.com/lists/oss-security/2026/01/15/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61728","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"b30644f429eabdac","cpes":["cpe:2.3:a:gzip:gzip:1.13-1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/debian/gzip@1.13-1?arch=amd64&distro=debian-13.6","type":"deb","version":"1.13-1","language":"","licenses":["FSF-manpages","GFDL-1.3+-no-invariant","GFDL-3","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/gzip.list"},{"path":"/var/lib/dpkg/info/gzip.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/gzip.postinst"},{"path":"/var/lib/dpkg/info/gzip.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/gzip.preinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.13-1+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41992","versionConstraint":"< 1.13-1+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"gzip","version":"1.13-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-41992","fix":{"state":"fixed","versions":["1.13-1+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.13-1+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-08","epss":0.00564,"percentile":0.4513}],"risk":0.42300000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41992","description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.  This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d."},"relatedVulnerabilities":[{"id":"CVE-2026-41992","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-08","epss":0.00564,"percentile":0.4513}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=e7378c2d421be6a286922374425680bbe9ad8b7d","https://www.gnu.org/software/gzip/","http://www.openwall.com/lists/oss-security/2026/08/23/1","http://www.openwall.com/lists/oss-security/2026/08/25/1","http://www.openwall.com/lists/oss-security/2026/08/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41992","description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80229","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"risk":0.42224999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations."},"relatedVulnerabilities":[{"id":"CVE-2026-80229","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80229","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"risk":0.42224999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations."},"relatedVulnerabilities":[{"id":"CVE-2026-80229","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80229","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"risk":0.42224999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations."},"relatedVulnerabilities":[{"id":"CVE-2026-80229","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5038","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5038","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"risk":0.42,"urls":["https://go.dev/cl/774481","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79217","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-42504","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"urls":["https://go.dev/cl/774481","https://go.dev/issue/79217","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5038"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42504","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."}]},{"artifact":{"id":"99d64a21b6e327fd","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=libssh2","type":"deb","version":"1.11.1-1+deb13u1","language":"","licenses":["BSD3","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libssh2-1t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66035","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"libssh2","version":"1.11.1-1+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66035","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66035","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66035","date":"2026-10-08","epss":0.00551,"percentile":0.44337}],"risk":0.4187600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66035","description":"libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication."},"relatedVulnerabilities":[{"id":"CVE-2026-66035","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66035","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66035","date":"2026-10-08","epss":0.00551,"percentile":0.44337}],"urls":["https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4","https://github.com/libssh2/libssh2/pull/2198","https://www.vulncheck.com/advisories/libssh2-heap-buffer-overflow-via-etm-cipher-negotiation"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66035","description":"libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication."}]},{"artifact":{"id":"ca88752821693d8d","cpes":["cpe:2.3:a:patch:patch:2.8-2:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.8-2?arch=amd64&distro=debian-13.6","type":"deb","version":"2.8-2","language":"","licenses":["GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6951","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"patch","version":"2.8-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-6951","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6951","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6951","date":"2026-10-08","epss":0.08359,"percentile":0.94832}],"risk":0.41795,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6951","description":"An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a \"mangled rename\" issue."},"relatedVulnerabilities":[{"id":"CVE-2018-6951","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6951","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6951","date":"2026-10-08","epss":0.08359,"percentile":0.94832}],"urls":["http://www.securityfocus.com/bid/103044","https://git.savannah.gnu.org/cgit/patch.git/commit/?id=f290f48a621867084884bfff87f8093c15195e6a","https://savannah.gnu.org/bugs/index.php?53132","https://security.gentoo.org/glsa/201904-17","https://usn.ubuntu.com/3624-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6951","description":"An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a \"mangled rename\" issue."}]},{"artifact":{"id":"ca88752821693d8d","cpes":["cpe:2.3:a:patch:patch:2.8-2:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.8-2?arch=amd64&distro=debian-13.6","type":"deb","version":"2.8-2","language":"","licenses":["GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6952","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"patch","version":"2.8-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-6952","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6952","date":"2026-10-08","epss":0.0819,"percentile":0.94738}],"risk":0.40950000000000003,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6952","description":"A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6."},"relatedVulnerabilities":[{"id":"CVE-2018-6952","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6952","date":"2026-10-08","epss":0.0819,"percentile":0.94738}],"urls":["http://www.securityfocus.com/bid/103047","https://access.redhat.com/errata/RHSA-2019:2033","https://savannah.gnu.org/bugs/index.php?53133","https://security.gentoo.org/glsa/201904-17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6952","description":"A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8926","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8926","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"risk":0.40182000000000007,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user."},"relatedVulnerabilities":[{"id":"CVE-2026-8926","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8926","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8926","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"risk":0.40182000000000007,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user."},"relatedVulnerabilities":[{"id":"CVE-2026-8926","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8926","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8926","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"risk":0.40182000000000007,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user."},"relatedVulnerabilities":[{"id":"CVE-2026-8926","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"risk":0.39096000000000003,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"risk":0.39096000000000003,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"risk":0.39096000000000003,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"risk":0.39096000000000003,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.  When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.  A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42496","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"risk":0.38915,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path."},"relatedVulnerabilities":[{"id":"CVE-2026-42496","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"impactScore":6.1,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42496","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"risk":0.38915,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path."},"relatedVulnerabilities":[{"id":"CVE-2026-42496","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"impactScore":6.1,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42496","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"risk":0.38915,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path."},"relatedVulnerabilities":[{"id":"CVE-2026-42496","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"impactScore":6.1,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42496","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"risk":0.38915,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.  _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.  A subsequent open through the extracted name reads or writes the attacker chosen path."},"relatedVulnerabilities":[{"id":"CVE-2026-42496","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"impactScore":6.1,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"risk":0.37867500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege."},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"risk":0.37867500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege."},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"risk":0.37867500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege."},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"risk":0.37867500000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.  _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.  Arbitrary Perl in the output glob executes at the calling process's privilege."},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.56.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6355","versionConstraint":"<0.56.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6355","fix":{"state":"fixed","versions":["0.56.0"],"available":[{"date":"2026-09-02","kind":"release","version":"0.56.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56855","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56855","date":"2026-10-08","epss":0.005,"percentile":0.4091}],"risk":0.375,"urls":["https://go.dev/cl/826524","https://groups.google.com/g/golang-announce/c/1y3fb2np35U"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/81317","description":"Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.\n\nNow, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking."},"relatedVulnerabilities":[{"id":"CVE-2026-56855","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56855","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56855","date":"2026-10-08","epss":0.005,"percentile":0.4091}],"urls":["https://go.dev/cl/826524","https://go.dev/issue/81317","https://groups.google.com/g/golang-announce/c/1y3fb2np35U","https://pkg.go.dev/vuln/GO-2026-6355"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56855","description":"Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"< 2.41-12+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"fixed","versions":["2.41-12+deb13u4"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"2.41-12+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"< 2.41-12+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"fixed","versions":["2.41-12+deb13u4"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"2.41-12+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"risk":0.36556,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed."},"relatedVulnerabilities":[{"id":"CVE-2026-9080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"risk":0.36556,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed."},"relatedVulnerabilities":[{"id":"CVE-2026-9080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"risk":0.36556,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed."},"relatedVulnerabilities":[{"id":"CVE-2026-9080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed."}]},{"artifact":{"id":"99d64a21b6e327fd","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=libssh2","type":"deb","version":"1.11.1-1+deb13u1","language":"","licenses":["BSD3","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libssh2-1t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66032","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"libssh2","version":"1.11.1-1+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66032","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66032","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66032","date":"2026-10-08","epss":0.00448,"percentile":0.36954}],"risk":0.3628799999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66032","description":"libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites."},"relatedVulnerabilities":[{"id":"CVE-2026-66032","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66032","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66032","date":"2026-10-08","epss":0.00448,"percentile":0.36954}],"urls":["https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0","https://github.com/libssh2/libssh2/pull/2180","https://www.vulncheck.com/advisories/libssh2-double-free-heap-corruption-via-sftp-open"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66032","description":"libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80255","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host."},"relatedVulnerabilities":[{"id":"CVE-2026-80255","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80255","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host."},"relatedVulnerabilities":[{"id":"CVE-2026-80255","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80255","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host."},"relatedVulnerabilities":[{"id":"CVE-2026-80255","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"0c6f9f8288843347","cpes":["cpe:2.3:a:golang:text:v0.23.0:*:*:*:*:*:*:*"],"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.23.0","type":"go-module","version":"v0.23.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:D71I7dUrlY+VX0gQShAThNGHFxZ13dGLBHQLVl1mJlY=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.39.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5970","versionConstraint":"<0.39.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/text","version":"v0.23.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5970","fix":{"state":"fixed","versions":["0.39.0"],"available":[{"date":"2026-06-30","kind":"release","version":"0.39.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56852","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56852","date":"2026-10-08","epss":0.00475,"percentile":0.39076}],"risk":0.35624999999999996,"urls":["https://go.dev/cl/794100"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80142","description":"A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-56852","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56852","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56852","date":"2026-10-08","epss":0.00475,"percentile":0.39076}],"urls":["https://go.dev/cl/794100","https://go.dev/issue/80142","https://pkg.go.dev/vuln/GO-2026-5970"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56852","description":"A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"risk":0.35325,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"risk":0.35325,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"risk":0.35325,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"risk":0.35325,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.  _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.  A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"614dd2dfa62b9595","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.6&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap2/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libldap2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-17740","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2017-17740","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-08","epss":0.07022,"percentile":0.94018}],"risk":0.3511,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."},"relatedVulnerabilities":[{"id":"CVE-2017-17740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-08","epss":0.07022,"percentile":0.94018}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://www.openldap.org/its/index.cgi/Incoming?id=8759","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary.  Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer.  To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary.  Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer.  To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary.  Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer.  To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4155","versionConstraint":"<1.24.11||>=1.25.0,<1.25.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4155","fix":{"state":"fixed","versions":["1.24.11","1.25.5"],"available":[{"date":"2025-12-02","kind":"release","version":"1.24.11"},{"date":"2025-12-02","kind":"release","version":"1.25.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"risk":0.34275,"urls":["https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/725920","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"urls":["https://go.dev/cl/725920","https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4","https://pkg.go.dev/vuln/GO-2025-4155"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61729","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."}]},{"artifact":{"id":"7402a3d31bb024db","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64&distro=debian-13.6&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"3f9378db54aaac9e","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all&distro=debian-13.6&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"e96cb50e09a471e0","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64&distro=debian-13.6&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-78mq-xcr3-xm33","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-78mq-xcr3-xm33","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39835","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39835","cwe":"CWE-476","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39835","date":"2026-10-08","epss":0.00662,"percentile":0.50108}],"risk":0.34093,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39835","https://go.dev/cl/781660","https://go.dev/issue/79563","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5015","https://access.redhat.com/security/cve/CVE-2026-39835","https://bugzilla.redhat.com/show_bug.cgi?id=2480680","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39835.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47949","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51038","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:51036","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-78mq-xcr3-xm33","description":"golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow"},"relatedVulnerabilities":[{"id":"CVE-2026-39835","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39835","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39835","cwe":"CWE-476","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39835","date":"2026-10-08","epss":0.00662,"percentile":0.50108}],"urls":["https://go.dev/cl/781660","https://go.dev/issue/79563","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5015","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47949","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51036","https://access.redhat.com/errata/RHSA-2026:51038","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/security/cve/CVE-2026-39835","https://bugzilla.redhat.com/show_bug.cgi?id=2480680","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39835.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39835","description":"SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.33847,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.33847,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.33847,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.33847,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.  In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.  Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"risk":0.33558,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"risk":0.33558,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"risk":0.33558,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"risk":0.33558,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.  retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.  A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"99d64a21b6e327fd","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=libssh2","type":"deb","version":"1.11.1-1+deb13u1","language":"","licenses":["BSD3","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libssh2-1t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58050","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"libssh2","version":"1.11.1-1+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58050","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58050","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58050","date":"2026-10-08","epss":0.00444,"percentile":0.36629}],"risk":0.3330000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58050","description":"libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client."},"relatedVulnerabilities":[{"id":"CVE-2026-58050","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58050","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58050","date":"2026-10-08","epss":0.00444,"percentile":0.36629}],"urls":["https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc","https://github.com/libssh2/libssh2/blob/master/src/publickey.c","https://www.vulncheck.com/advisories/libssh2-integer-overflow-in-publickey-subsystem-attribute-allocation"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58050","description":"libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6303","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6303","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-08-11","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56854","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56854","date":"2026-10-08","epss":0.00437,"percentile":0.36015}],"risk":0.32775,"urls":["https://go.dev/cl/797040"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80213","description":"The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback."},"relatedVulnerabilities":[{"id":"CVE-2026-56854","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56854","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56854","date":"2026-10-08","epss":0.00437,"percentile":0.36015}],"urls":["https://go.dev/cl/797040","https://go.dev/issue/80213","https://pkg.go.dev/vuln/GO-2026-6303"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56854","description":"The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback."}]},{"artifact":{"id":"5e92736840e45ef8","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.2-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.2-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=expat","type":"deb","version":"2.8.2-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"expat","version":"2.8.2-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.32642999999999994,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.56.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6354","versionConstraint":"<0.56.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6354","fix":{"state":"fixed","versions":["0.56.0"],"available":[{"date":"2026-09-02","kind":"release","version":"0.56.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78662","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-78662","date":"2026-10-08","epss":0.00431,"percentile":0.3535}],"risk":0.32325,"urls":["https://go.dev/cl/826504","https://groups.google.com/g/golang-announce/c/1y3fb2np35U"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/81316","description":"Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection.\n\nNow, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection."},"relatedVulnerabilities":[{"id":"CVE-2026-78662","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78662","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-78662","date":"2026-10-08","epss":0.00431,"percentile":0.3535}],"urls":["https://go.dev/cl/826504","https://go.dev/issue/81316","https://groups.google.com/g/golang-announce/c/1y3fb2np35U","https://pkg.go.dev/vuln/GO-2026-6354"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78662","description":"Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.32046,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth.  Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack.  This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely.     The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.32046,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth.  Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack.  This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely.     The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.32046,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth.  Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack.  This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely.     The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"15791da16e435065","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"229bfebd2f7fc7f3","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"82f554653d484779","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"fb348d32a9e96833","cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"a8b3fa3699849e35","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"a8a27df4740c7b35","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"dd4a8fd9dddb7191","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:4.16.0-2+really2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"0875fd1d871c7e1b","cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"afc98bf002d364bb","cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.6","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"c8ce23e36f4d6bca","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=pcre2","type":"deb","version":"10.46-1~deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"fix":{"suggestedVersion":"10.46-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"< 10.46-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pcre2","version":"10.46-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"fixed","versions":["10.46-1~deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"10.46-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.30928999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"risk":0.30600000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.  When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-9545","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"risk":0.30600000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.  When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-9545","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"risk":0.30600000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.  When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-9545","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."}]},{"artifact":{"id":"99d64a21b6e327fd","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=libssh2","type":"deb","version":"1.11.1-1+deb13u1","language":"","licenses":["BSD3","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libssh2-1t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66034","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"libssh2","version":"1.11.1-1+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66034","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66034","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66034","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66034","date":"2026-10-08","epss":0.00402,"percentile":0.32385}],"risk":0.30552,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66034","description":"libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region."},"relatedVulnerabilities":[{"id":"CVE-2026-66034","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66034","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66034","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66034","date":"2026-10-08","epss":0.00402,"percentile":0.32385}],"urls":["https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9","https://github.com/libssh2/libssh2/pull/2202","https://www.vulncheck.com/advisories/libssh2-heap-out-of-bounds-read-via-publickey-subsystem"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66034","description":"libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-45gg-vh54-h5m9","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-45gg-vh54-h5m9","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39828","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39828","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39828","date":"2026-10-08","epss":0.00539,"percentile":0.43577}],"risk":0.30453499999999994,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39828","https://go.dev/cl/781621","https://go.dev/issue/79562","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5014","https://access.redhat.com/security/cve/CVE-2026-39828","https://bugzilla.redhat.com/show_bug.cgi?id=2480687","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39828.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40119","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41055"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-45gg-vh54-h5m9","description":"golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions"},"relatedVulnerabilities":[{"id":"CVE-2026-39828","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39828","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39828","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39828","date":"2026-10-08","epss":0.00539,"percentile":0.43577}],"urls":["https://go.dev/cl/781621","https://go.dev/issue/79562","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5014","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51038","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/security/cve/CVE-2026-39828","https://bugzilla.redhat.com/show_bug.cgi?id=2480687","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39828.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39828","description":"When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84784","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use.  Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired.  The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame.  Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth.  [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84784","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use.  Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired.  The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame.  Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth.  [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84784","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use.  Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired.  The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame.  Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth.  [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48961","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48961","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-08","epss":0.00407,"percentile":0.329}],"risk":0.30118,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48961","description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool."},"relatedVulnerabilities":[{"id":"CVE-2026-48961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-08","epss":0.00407,"percentile":0.329}],"urls":["https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48961","description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-48961","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48961","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-08","epss":0.00407,"percentile":0.329}],"risk":0.30118,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48961","description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool."},"relatedVulnerabilities":[{"id":"CVE-2026-48961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-08","epss":0.00407,"percentile":0.329}],"urls":["https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48961","description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48961","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48961","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-08","epss":0.00407,"percentile":0.329}],"risk":0.30118,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48961","description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool."},"relatedVulnerabilities":[{"id":"CVE-2026-48961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-08","epss":0.00407,"percentile":0.329}],"urls":["https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48961","description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48961","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48961","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-08","epss":0.00407,"percentile":0.329}],"risk":0.30118,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48961","description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.  When decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.  Library callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool."},"relatedVulnerabilities":[{"id":"CVE-2026-48961","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48961","cwe":"CWE-755","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48961","date":"2026-10-08","epss":0.00407,"percentile":0.329}],"urls":["https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48961","description":"IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.\n\nWhen decode_ux() in bin/zipdetails handles an Info-ZIP Unix Extra Field (tag 0x7875) with UID Size or GID Size set to 8, causing zipdetails to decode an 8-byte UID or GID value, it dispatches through decodeLitteEndian(), which calls a misnamed helper unpackValueQ. The actual function defined in the same file is unpackValue_Q (with underscore); the call raises 'Undefined subroutine &main::unpackValueQ' and the script exits with status 255.\n\nLibrary callers of IO::Compress and IO::Uncompress are not affected; the defect is in the bundled CLI tool."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"1f32975dfd37be95","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/debian/libpam-modules@1.7.0-5?arch=amd64&distro=debian-13.6&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"cb7fdbb7b6a04bdc","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/debian/libpam-modules-bin@1.7.0-5?arch=amd64&distro=debian-13.6&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"eb5873c5c35e21b8","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/debian/libpam-runtime@1.7.0-5?arch=all&distro=debian-13.6&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"1c6c7728b37b94de","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/debian/libpam0g@1.7.0-5?arch=amd64&distro=debian-13.6&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"efad814c9c04e9fa","cpes":["cpe:2.3:a:golang:networking:v0.38.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.38.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.38.0","type":"go-module","version":"v0.38.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4440","versionConstraint":"<0.45.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.38.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4440","fix":{"state":"fixed","versions":["0.45.0"],"available":[{"date":"2025-10-07","kind":"release","version":"0.45.0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-47911","date":"2026-10-08","epss":0.0057,"percentile":0.454}],"risk":0.29355000000000003,"urls":["https://github.com/golang/vulndb/issues/4440","https://groups.google.com/g/golang-announce/c/jnQcOYpiR2c"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709876","description":"The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content."},"relatedVulnerabilities":[{"id":"CVE-2025-47911","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-47911","date":"2026-10-08","epss":0.0057,"percentile":0.454}],"urls":["https://github.com/golang/vulndb/issues/4440","https://go.dev/cl/709876","https://groups.google.com/g/golang-announce/c/jnQcOYpiR2c","https://pkg.go.dev/vuln/GO-2026-4440"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47911","description":"The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j5w8-q4qc-rx2x","versionConstraint":"<0.45.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-j5w8-q4qc-rx2x","fix":{"state":"fixed","versions":["0.45.0"],"available":[{"date":"2025-11-20","kind":"first-observed","version":"0.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58181","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-58181","date":"2026-10-08","epss":0.00561,"percentile":0.44933}],"risk":0.28891500000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-58181","https://go.dev/cl/721961","https://go.dev/issue/76363","https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA","https://pkg.go.dev/vuln/GO-2025-4134"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j5w8-q4qc-rx2x","description":"golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption"},"relatedVulnerabilities":[{"id":"CVE-2025-58181","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58181","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-58181","date":"2026-10-08","epss":0.00561,"percentile":0.44933}],"urls":["https://go.dev/cl/721961","https://go.dev/issue/76363","https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA","https://pkg.go.dev/vuln/GO-2025-4134"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58181","description":"SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2008-3234","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-3234","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-3234","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3234","date":"2026-10-08","epss":0.05773,"percentile":0.92898}],"risk":0.28865,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-3234","description":"sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username."},"relatedVulnerabilities":[{"id":"CVE-2008-3234","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6.5,"impactScore":6.5,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-3234","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3234","date":"2026-10-08","epss":0.05773,"percentile":0.92898}],"urls":["http://www.securityfocus.com/bid/30276","https://exchange.xforce.ibmcloud.com/vulnerabilities/44037","https://www.exploit-db.com/exploits/6094"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-3234","description":"sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"efad814c9c04e9fa","cpes":["cpe:2.3:a:golang:networking:v0.38.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.38.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.38.0","type":"go-module","version":"v0.38.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4441","versionConstraint":"<0.45.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.38.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4441","fix":{"state":"fixed","versions":["0.45.0"],"available":[{"date":"2025-10-07","kind":"release","version":"0.45.0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58190","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58190","date":"2026-10-08","epss":0.00548,"percentile":0.44137}],"risk":0.28221999999999997,"urls":["https://github.com/golang/vulndb/issues/4441","https://go.dev/cl/709875"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/jnQcOYpiR2c","description":"The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content."},"relatedVulnerabilities":[{"id":"CVE-2025-58190","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58190","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58190","date":"2026-10-08","epss":0.00548,"percentile":0.44137}],"urls":["https://github.com/golang/vulndb/issues/4441","https://go.dev/cl/709875","https://groups.google.com/g/golang-announce/c/jnQcOYpiR2c","https://pkg.go.dev/vuln/GO-2026-4441"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58190","description":"The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content."}]},{"artifact":{"id":"8a1ec6d9372df578","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.6&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-60002","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"risk":0.276,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"},"relatedVulnerabilities":[{"id":"CVE-2026-60002","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-08","epss":0.003,"percentile":0.20792}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"}]},{"artifact":{"id":"8a928cc6733b8d4c","cpes":["cpe:2.3:a:gcc-14-base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-base","purl":"pkg:deb/debian/gcc-14-base@14.2.0-19?arch=amd64&distro=debian-13.6&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/gcc-14-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"2338ed612a82adf3","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@14.2.0-19?arch=amd64&distro=debian-13.6&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"7dc961cf921ecd08","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@14.2.0-19?arch=amd64&distro=debian-13.6&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20012","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2016-20012","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20012","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-20012","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-20012","date":"2026-10-08","epss":0.05326,"percentile":0.92406}],"risk":0.26630000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-20012","description":"OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product"},"relatedVulnerabilities":[{"id":"CVE-2016-20012","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20012","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-20012","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-20012","date":"2026-10-08","epss":0.05326,"percentile":0.92406}],"urls":["https://github.com/openssh/openssh-portable/blob/d0fffc88c8fe90c1815c6f4097bc8cbcabc0f3dd/auth2-pubkey.c#L261-L265","https://github.com/openssh/openssh-portable/pull/270","https://github.com/openssh/openssh-portable/pull/270#issuecomment-920577097","https://github.com/openssh/openssh-portable/pull/270#issuecomment-943909185","https://rushter.com/blog/public-ssh-keys/","https://security.netapp.com/advisory/ntap-20211014-0005/","https://utcc.utoronto.ca/~cks/space/blog/tech/SSHKeysAreInfoLeak","https://www.openwall.com/lists/oss-security/2018/08/24/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20012","description":"OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product"}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4946","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4946","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"risk":0.26625,"urls":["https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758061","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service.\n\nThis only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."},"relatedVulnerabilities":[{"id":"CVE-2026-32281","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"urls":["https://go.dev/cl/758061","https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4946"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32281","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9m57-25v3-79x9","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-9m57-25v3-79x9","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46598","cwe":"CWE-129","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46598","date":"2026-10-08","epss":0.00515,"percentile":0.42036}],"risk":0.265225,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-46598","https://go.dev/cl/781360","https://go.dev/issue/79596","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5033"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9m57-25v3-79x9","description":"golang.org/x/crypto: Invoking pathological inputs can lead to client panic"},"relatedVulnerabilities":[{"id":"CVE-2026-46598","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46598","cwe":"CWE-129","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46598","date":"2026-10-08","epss":0.00515,"percentile":0.42036}],"urls":["https://go.dev/cl/781360","https://go.dev/issue/79596","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5033"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46598","description":"For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used."}]},{"artifact":{"id":"efad814c9c04e9fa","cpes":["cpe:2.3:a:golang:networking:v0.38.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.38.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.38.0","type":"go-module","version":"v0.38.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5cv4-jp36-h3mw","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.38.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-5cv4-jp36-h3mw","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-07-02","kind":"first-observed","version":"0.55.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25680","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25680","date":"2026-10-08","epss":0.0046,"percentile":0.37848}],"risk":0.26449999999999996,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-25680","https://go.dev/cl/781702","https://go.dev/issue/79573","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5028","https://go.googlesource.com/net/+/08be507abce89191d78cd49da60f4501fc910472","https://go.googlesource.com/net/+/refs/tags/v0.55.0"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5cv4-jp36-h3mw","description":"Go Net HTML parser is vulnerable to denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-25680","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25680","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25680","date":"2026-10-08","epss":0.0046,"percentile":0.37848}],"urls":["https://go.dev/cl/781702","https://go.dev/issue/79573","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5028"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25680","description":"Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service."}]},{"artifact":{"id":"614dd2dfa62b9595","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.6&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap2/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libldap2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-3276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2015-3276","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-08","epss":0.05269,"percentile":0.92348}],"risk":0.26345,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."},"relatedVulnerabilities":[{"id":"CVE-2015-3276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-08","epss":0.05269,"percentile":0.92348}],"urls":["http://rhn.redhat.com/errata/RHSA-2015-2131.html","http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","http://www.securitytracker.com/id/1034221","https://bugzilla.redhat.com/show_bug.cgi?id=1238322"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f6x5-jh6r-wrfv","versionConstraint":"<0.45.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-f6x5-jh6r-wrfv","fix":{"state":"fixed","versions":["0.45.0"],"available":[{"date":"2025-11-21","kind":"first-observed","version":"0.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47914","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-47914","date":"2026-10-08","epss":0.0051,"percentile":0.41611}],"risk":0.26265000000000005,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-47914","https://go.dev/cl/721960","https://go.dev/issue/76364","https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA","https://pkg.go.dev/vuln/GO-2025-4135"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f6x5-jh6r-wrfv","description":"golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read"},"relatedVulnerabilities":[{"id":"CVE-2025-47914","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47914","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-47914","date":"2026-10-08","epss":0.0051,"percentile":0.41611}],"urls":["https://go.dev/cl/721960","https://go.dev/issue/76364","https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA","https://pkg.go.dev/vuln/GO-2025-4135"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47914","description":"SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"ca88752821693d8d","cpes":["cpe:2.3:a:patch:patch:2.8-2:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.8-2?arch=amd64&distro=debian-13.6","type":"deb","version":"2.8-2","language":"","licenses":["GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2010-4651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"patch","version":"2.8-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4651","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4651","date":"2026-10-08","epss":0.04874,"percentile":0.91829}],"risk":0.2437,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4651","description":"Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679."},"relatedVulnerabilities":[{"id":"CVE-2010-4651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4651","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4651","date":"2026-10-08","epss":0.04874,"percentile":0.91829}],"urls":["http://git.savannah.gnu.org/cgit/patch.git/commit/?id=685a78b6052f4df6eac6d625a545cfb54a6ac0e1","http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055241.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055246.html","http://lists.gnu.org/archive/html/bug-patch/2010-12/msg00000.html","http://openwall.com/lists/oss-security/2011/01/05/10","http://openwall.com/lists/oss-security/2011/01/06/19","http://openwall.com/lists/oss-security/2011/01/06/20","http://openwall.com/lists/oss-security/2011/01/06/21","http://secunia.com/advisories/43663","http://secunia.com/advisories/43677","http://support.apple.com/kb/HT4723","http://www.securityfocus.com/bid/46768","http://www.vupen.com/english/advisories/2011/0600","https://bugzilla.redhat.com/show_bug.cgi?id=667529"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4651","description":"Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"0e674e420f2bfafa","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=sqlite3","type":"deb","version":"3.46.1-7+deb13u1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.46.1-7+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11822","versionConstraint":"< 3.46.1-7+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11822","fix":{"state":"fixed","versions":["3.46.1-7+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"3.46.1-7+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"risk":0.2352,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."},"relatedVulnerabilities":[{"id":"CVE-2026-11822","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"99d64a21b6e327fd","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1\\+deb13u1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=libssh2","type":"deb","version":"1.11.1-1+deb13u1","language":"","licenses":["BSD3","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssh2-1t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libssh2-1t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libssh2-1t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58051","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"libssh2","version":"1.11.1-1+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58051","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58051","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58051","date":"2026-10-08","epss":0.00277,"percentile":0.1843}],"risk":0.21883000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58051","description":"libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client."},"relatedVulnerabilities":[{"id":"CVE-2026-58051","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58051","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58051","date":"2026-10-08","epss":0.00277,"percentile":0.1843}],"urls":["https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc","https://github.com/libssh2/libssh2/blob/master/src/publickey.c","https://www.vulncheck.com/advisories/libssh2-free-of-uninitialized-pointer-in-publickey-list-cleanup"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58051","description":"libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-55654","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-55654","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55654","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-55654","date":"2026-10-08","epss":0.00652,"percentile":0.49675}],"risk":0.21841999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-55654","description":"A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service."},"relatedVulnerabilities":[{"id":"CVE-2026-55654","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55654","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-55654","date":"2026-10-08","epss":0.00652,"percentile":0.49675}],"urls":["https://access.redhat.com/errata/RHSA-2026:36759","https://access.redhat.com/errata/RHSA-2026:47756","https://access.redhat.com/errata/RHSA-2026:47757","https://access.redhat.com/errata/RHSA-2026:54387","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-55654","https://bugzilla.redhat.com/show_bug.cgi?id=2462493"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55654","description":"A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4980","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4980","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"risk":0.21811499999999998,"urls":["https://go.dev/cl/771180","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78981","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."},"relatedVulnerabilities":[{"id":"CVE-2026-39826","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"urls":["https://go.dev/cl/771180","https://go.dev/issue/78981","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4980"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39826","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.21527,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.21527,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.21527,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.21527,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.  The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.  Example:    \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE   \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed  An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"5e92736840e45ef8","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.2-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.2-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=expat","type":"deb","version":"2.8.2-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76956","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"expat","version":"2.8.2-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76956","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76956","cwe":"CWE-394","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76956","date":"2026-10-08","epss":0.00287,"percentile":0.19503}],"risk":0.21525,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76956","description":"In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content."},"relatedVulnerabilities":[{"id":"CVE-2026-76956","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76956","cwe":"CWE-394","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76956","date":"2026-10-08","epss":0.00287,"percentile":0.19503}],"urls":["https://github.com/libexpat/libexpat/pull/1326","https://github.com/libexpat/libexpat/pull/1329"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76956","description":"In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4976","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4976","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"risk":0.212695,"urls":["https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/770541","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions.\n\nWhen used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function.\n\nFor example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."},"relatedVulnerabilities":[{"id":"CVE-2026-39825","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"urls":["https://go.dev/cl/770541","https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4976"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39825","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5039","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5039","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"risk":0.21218,"urls":["https://go.dev/cl/777060","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79346","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."},"relatedVulnerabilities":[{"id":"CVE-2026-42507","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"urls":["https://go.dev/cl/777060","https://go.dev/issue/79346","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5039"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42507","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."}]},{"artifact":{"id":"213d133cc46bf69b","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.6","type":"deb","version":"1.35+dfsg-3.1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5704","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5704","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"risk":0.210525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."},"relatedVulnerabilities":[{"id":"CVE-2026-5704","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"urls":["https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66514","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-5704","https://bugzilla.redhat.com/show_bug.cgi?id=2455360","http://www.openwall.com/lists/oss-security/2026/04/11/10","http://www.openwall.com/lists/oss-security/2026/04/11/11","http://www.openwall.com/lists/oss-security/2026/04/12/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.20996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.  Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages.  CWE: CWE-354 (Improper Validation of Integrity Check Value)  Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case.  FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module."},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.20996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.  Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages.  CWE: CWE-354 (Improper Validation of Integrity Check Value)  Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case.  FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module."},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.20996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.  Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages.  CWE: CWE-354 (Improper Validation of Integrity Check Value)  Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case.  FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module."},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"c8ce23e36f4d6bca","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=pcre2","type":"deb","version":"10.46-1~deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"fix":{"suggestedVersion":"10.46-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"< 10.46-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pcre2","version":"10.46-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"fixed","versions":["10.46-1~deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"10.46-1~deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.20711,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7010","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."},"relatedVulnerabilities":[{"id":"CVE-2026-7010","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7010","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."},"relatedVulnerabilities":[{"id":"CVE-2026-7010","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7010","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."},"relatedVulnerabilities":[{"id":"CVE-2026-7010","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7010","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7010","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.  The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.  An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."},"relatedVulnerabilities":[{"id":"CVE-2026-7010","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7010","cwe":"CWE-113","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7010","date":"2026-10-08","epss":0.0036,"percentile":0.27739}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d.patch","https://metacpan.org/release/HAARG/HTTP-Tiny-0.093-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/05/11/17"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7010","description":"HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.\n\nThe unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values.\n\nAn attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server."}]},{"artifact":{"id":"213d133cc46bf69b","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.6","type":"deb","version":"1.35+dfsg-3.1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2005-2541","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2005-2541","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"risk":0.1996,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."},"relatedVulnerabilities":[{"id":"CVE-2005-2541","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"urls":["http://marc.info/?l=bugtraq&m=112327628230258&w=2","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected.  Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags.  An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process.  Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3.  The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity.  FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected.  Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags.  An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process.  Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3.  The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity.  FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected.  Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags.  An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process.  Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3.  The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity.  FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.  Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.  CWE: CWE-1284: Improper Validation of Specified Quantity in Input  Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.  In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.  The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.  Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.  CWE: CWE-1284: Improper Validation of Specified Quantity in Input  Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.  In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.  The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.  Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.  CWE: CWE-1284: Improper Validation of Specified Quantity in Input  Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.  In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.  The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5856","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5856","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"risk":0.19673,"urls":["https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/775960","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."},"relatedVulnerabilities":[{"id":"CVE-2026-42505","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"urls":["https://go.dev/cl/775960","https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-5856"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42505","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4603","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4603","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"risk":0.19202999999999998,"urls":["https://go.dev/issue/77954","https://go.dev/cl/752081"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\".\n\nA new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."},"relatedVulnerabilities":[{"id":"CVE-2026-27142","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"urls":["https://go.dev/cl/752081","https://go.dev/issue/77954","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4603"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27142","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."}]},{"artifact":{"id":"5e92736840e45ef8","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.2-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.2-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=expat","type":"deb","version":"2.8.2-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"expat","version":"2.8.2-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"risk":0.18966000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"efad814c9c04e9fa","cpes":["cpe:2.3:a:golang:networking:v0.38.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.38.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.38.0","type":"go-module","version":"v0.38.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5025","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.38.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5025","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42506","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42506","date":"2026-10-08","epss":0.00333,"percentile":0.2444}],"risk":0.18481499999999998,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781700"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79571","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-42506","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42506","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42506","date":"2026-10-08","epss":0.00333,"percentile":0.2444}],"urls":["https://go.dev/cl/781700","https://go.dev/issue/79571","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42506","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4865","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4865","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763762","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied.\n\nThese issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."},"relatedVulnerabilities":[{"id":"CVE-2026-32289","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/763762","https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4865"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32289","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4982","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4982","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/cl/769920","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78913","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-39823","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/769920","https://go.dev/issue/78913","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4982"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39823","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits.  Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data.  Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error.  The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met:   - the remote peer opens several streams   - each stream must stay within the stream-level flow control limit   - there must be no zero-offset byte sent on any of the streams     (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits.  Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data.  Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error.  The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met:   - the remote peer opens several streams   - each stream must stay within the stream-level flow control limit   - there must be no zero-offset byte sent on any of the streams     (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits.  Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data.  Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error.  The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met:   - the remote peer opens several streams   - each stream must stay within the stream-level flow control limit   - there must be no zero-offset byte sent on any of the streams     (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"8a928cc6733b8d4c","cpes":["cpe:2.3:a:gcc-14-base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-base","purl":"pkg:deb/debian/gcc-14-base@14.2.0-19?arch=amd64&distro=debian-13.6&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/gcc-14-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"2338ed612a82adf3","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@14.2.0-19?arch=amd64&distro=debian-13.6&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"7dc961cf921ecd08","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@14.2.0-19?arch=amd64&distro=debian-13.6&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7017","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"risk":0.18031,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-7017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7017","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"risk":0.18031,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-7017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7017","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"risk":0.18031,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-7017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7017","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"risk":0.18031,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.  When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.  The HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-7017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."}]},{"artifact":{"id":"de3bcbf9daefbcfb","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/debian/libnghttp2-14@1.64.0-1.1%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=nghttp2","type":"deb","version":"1.64.0-1.1+deb13u1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58055","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"nghttp2","version":"1.64.0-1.1+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58055","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-08","epss":0.00319,"percentile":0.22818}],"risk":0.18023499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-58055","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-08","epss":0.00319,"percentile":0.22818}],"urls":["https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc","https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e","https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."}]},{"artifact":{"id":"0fa9072a5bfd36b6","cpes":["cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-2:libsasl2_2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2-2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2_2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*"],"name":"libsasl2-2","purl":"pkg:deb/debian/libsasl2-2@2.1.28%2Bdfsg1-9?arch=amd64&distro=debian-13.6&upstream=cyrus-sasl2","type":"deb","version":"2.1.28+dfsg1-9","language":"","licenses":["BSD-2-clause","BSD-2.2-clause","BSD-3-Clause-Attribution","BSD-3-clause","BSD-3-clause-JANET","BSD-3-clause-PADL","BSD-4-clause-UC","FSFULLR","GPL-3","GPL-3+","IBM-as-is","MIT-CMU","MIT-Export","MIT-OpenVision","OpenLDAP","RSA-MD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-2/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libsasl2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"cyrus-sasl2","version":"2.1.28+dfsg1-9"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"risk":0.17850000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."},"relatedVulnerabilities":[{"id":"CVE-2026-107161","cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"urls":["https://access.redhat.com/security/cve/CVE-2026-107161","https://bugzilla.redhat.com/show_bug.cgi?id=2460420"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."}]},{"artifact":{"id":"175bd219d71968b9","cpes":["cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules-db:libsasl2_modules_db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2-modules-db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2_modules_db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2-modules-db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2_modules_db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2-modules-db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2_modules_db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-modules-db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_modules_db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*"],"name":"libsasl2-modules-db","purl":"pkg:deb/debian/libsasl2-modules-db@2.1.28%2Bdfsg1-9?arch=amd64&distro=debian-13.6&upstream=cyrus-sasl2","type":"deb","version":"2.1.28+dfsg1-9","language":"","licenses":["BSD-2-clause","BSD-2.2-clause","BSD-3-Clause-Attribution","BSD-3-clause","BSD-3-clause-JANET","BSD-3-clause-PADL","BSD-4-clause-UC","FSFULLR","GPL-3","GPL-3+","IBM-as-is","MIT-CMU","MIT-Export","MIT-OpenVision","OpenLDAP","RSA-MD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-modules-db/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libsasl2-modules-db/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"cyrus-sasl2","version":"2.1.28+dfsg1-9"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"risk":0.17850000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."},"relatedVulnerabilities":[{"id":"CVE-2026-107161","cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"urls":["https://access.redhat.com/security/cve/CVE-2026-107161","https://bugzilla.redhat.com/show_bug.cgi?id=2460420"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15919","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-15919","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15919","date":"2026-10-08","epss":0.03557,"percentile":0.89007}],"risk":0.17784999999999998,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15919","description":"Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or \"oracle\") as a vulnerability.'"},"relatedVulnerabilities":[{"id":"CVE-2018-15919","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15919","date":"2026-10-08","epss":0.03557,"percentile":0.89007}],"urls":["http://seclists.org/oss-sec/2018/q3/180","http://www.securityfocus.com/bid/105163","https://security.netapp.com/advisory/ntap-20181221-0001/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15919","description":"Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or \"oracle\") as a vulnerability.'"}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4970","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4970","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"risk":0.17748,"urls":["https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://go.dev/cl/797880"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79005","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /.\n\nFor example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."},"relatedVulnerabilities":[{"id":"CVE-2026-39822","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"urls":["https://go.dev/cl/797880","https://go.dev/issue/79005","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-4970"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39822","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"15791da16e435065","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"229bfebd2f7fc7f3","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"82f554653d484779","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"fb348d32a9e96833","cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"a8b3fa3699849e35","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"a8a27df4740c7b35","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"dd4a8fd9dddb7191","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:4.16.0-2+really2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"0875fd1d871c7e1b","cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"afc98bf002d364bb","cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.6","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6091","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6091","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"risk":0.17204999999999998,"urls":["https://go.dev/cl/807100","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80435","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-56858","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"urls":["https://go.dev/cl/807100","https://go.dev/issue/80435","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56858","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data.  Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth.  CWE: CWE-407: Inefficient Algorithmic Complexity  Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`.  By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data.  Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth.  CWE: CWE-407: Inefficient Algorithmic Complexity  Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`.  By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data.  Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth.  CWE: CWE-407: Inefficient Algorithmic Complexity  Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`.  By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4340","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4340","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61730","date":"2026-10-08","epss":0.00329,"percentile":0.23929}],"risk":0.169435,"urls":["https://go.dev/issue/76443","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/724120","description":"During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."},"relatedVulnerabilities":[{"id":"CVE-2025-61730","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61730","date":"2026-10-08","epss":0.00329,"percentile":0.23929}],"urls":["https://go.dev/cl/724120","https://go.dev/issue/76443","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4340"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61730","description":"During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.167745,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.167745,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.167745,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.167745,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.  S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.  A template derived from untrusted input can read heap memory past the buffer and return it to the caller."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-60001","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"risk":0.16732499999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."},"relatedVulnerabilities":[{"id":"CVE-2026-60001","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-08","epss":0.00291,"percentile":0.19829}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4864","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4864","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"risk":0.16644,"urls":["https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763761","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root.\n\nThe Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."},"relatedVulnerabilities":[{"id":"CVE-2026-32282","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"urls":["https://go.dev/cl/763761","https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4864"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32282","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4175","versionConstraint":"<1.24.11||>=1.25.0,<1.25.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4175","fix":{"state":"fixed","versions":["1.24.11","1.25.5"],"available":[{"date":"2025-12-02","kind":"release","version":"1.24.11"},{"date":"2025-12-02","kind":"release","version":"1.25.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61727","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61727","date":"2026-10-08","epss":0.00284,"percentile":0.1914}],"risk":0.1633,"urls":["https://go.dev/issue/76442","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/723900","description":"An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com."},"relatedVulnerabilities":[{"id":"CVE-2025-61727","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61727","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61727","date":"2026-10-08","epss":0.00284,"percentile":0.1914}],"urls":["https://go.dev/cl/723900","https://go.dev/issue/76442","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4","https://pkg.go.dev/vuln/GO-2025-4175"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61727","description":"An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"63b4b6b094894eb7","cpes":["cpe:2.3:a:golang:crypto:v0.36.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.36.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.36.0","type":"go-module","version":"v0.36.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:AnAEvhDddvBdpY+uR+MyHmuZzzNqXSe/GvuDeob5L34=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qpw4-5x99-6vjp","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.36.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-qpw4-5x99-6vjp","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39827","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39827","date":"2026-10-08","epss":0.00281,"percentile":0.18814}],"risk":0.16157499999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39827","https://go.dev/cl/781320","https://go.dev/issue/35127","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5016"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qpw4-5x99-6vjp","description":"golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-39827","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39827","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39827","date":"2026-10-08","epss":0.00281,"percentile":0.18814}],"urls":["https://go.dev/cl/781320","https://go.dev/issue/35127","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39827","description":"An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection."}]},{"artifact":{"id":"c8ce23e36f4d6bca","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=pcre2","type":"deb","version":"10.46-1~deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"fix":{"suggestedVersion":"10.46-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"< 10.46-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pcre2","version":"10.46-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"fixed","versions":["10.46-1~deb13u3"],"available":[{"date":"2026-09-29","kind":"advisory","version":"10.46-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.16157000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6530-1","link":"https://security-tracker.debian.org/tracker/DSA-6530-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"c8ce23e36f4d6bca","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=pcre2","type":"deb","version":"10.46-1~deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"fix":{"suggestedVersion":"10.46-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"< 10.46-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pcre2","version":"10.46-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"fixed","versions":["10.46-1~deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"10.46-1~deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.16023,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"c8ce23e36f4d6bca","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=pcre2","type":"deb","version":"10.46-1~deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"fix":{"suggestedVersion":"10.46-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"< 10.46-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pcre2","version":"10.46-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"fixed","versions":["10.46-1~deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"10.46-1~deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.1541,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"15791da16e435065","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"229bfebd2f7fc7f3","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"82f554653d484779","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"fb348d32a9e96833","cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"a8b3fa3699849e35","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"a8a27df4740c7b35","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"dd4a8fd9dddb7191","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:4.16.0-2+really2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"0875fd1d871c7e1b","cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"afc98bf002d364bb","cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.6","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"c8ce23e36f4d6bca","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=pcre2","type":"deb","version":"10.46-1~deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"fix":{"suggestedVersion":"10.46-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"< 10.46-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pcre2","version":"10.46-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"fixed","versions":["10.46-1~deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"10.46-1~deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.14202499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"893ab677af71bedc","cpes":["cpe:2.3:a:login.defs:login.defs:1\\:4.17.4-2:*:*:*:*:*:*:*"],"name":"login.defs","purl":"pkg:deb/debian/login.defs@1%3A4.17.4-2?arch=all&distro=debian-13.6&upstream=shadow","type":"deb","version":"1:4.17.4-2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login.defs/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/login.defs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.postinst"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.14057999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"a0c2eaa9ca5431ff","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.17.4-2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/debian/passwd@1%3A4.17.4-2?arch=amd64&distro=debian-13.6&upstream=shadow","type":"deb","version":"1:4.17.4-2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.14057999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"0e674e420f2bfafa","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=sqlite3","type":"deb","version":"3.46.1-7+deb13u1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.46.1-7+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11824","versionConstraint":"< 3.46.1-7+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11824","fix":{"state":"fixed","versions":["3.46.1-7+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"3.46.1-7+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11824","date":"2026-10-08","epss":0.00175,"percentile":0.06432}],"risk":0.14,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11824","description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5."},"relatedVulnerabilities":[{"id":"CVE-2026-11824","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11824","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11824","date":"2026-10-08","epss":0.00175,"percentile":0.06432}],"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-heap-buffer-overflow-via-fts5-fts5chunkiterate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11824","description":"SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.  Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake.  This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.  The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.  Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake.  This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.  The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.  Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake.  This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.  The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106552","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106552","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106552","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106552","date":"2026-10-08","epss":0.00291,"percentile":0.19813}],"risk":0.13385999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106552","description":"In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation."},"relatedVulnerabilities":[{"id":"CVE-2026-106552","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106552","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106552","date":"2026-10-08","epss":0.00291,"percentile":0.19813}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106552","description":"In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"8e03bdf0d5ec8f50","cpes":["cpe:2.3:a:git:git:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"git","purl":"pkg:deb/debian/git@1%3A2.47.3-0%2Bdeb13u1?arch=amd64&distro=debian-13.6","type":"deb","version":"1:2.47.3-0+deb13u1","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/git/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.list"},{"path":"/var/lib/dpkg/info/git.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.postinst"},{"path":"/var/lib/dpkg/info/git.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.postrm"},{"path":"/var/lib/dpkg/info/git.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.preinst"},{"path":"/var/lib/dpkg/info/git.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-24975","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"git","version":"1:2.47.3-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2022-24975","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-08","epss":0.02624,"percentile":0.85025}],"risk":0.1312,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."},"relatedVulnerabilities":[{"id":"CVE-2022-24975","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-08","epss":0.02624,"percentile":0.85025}],"urls":["https://github.com/git/git/blob/2dc94da3744bfbbf145eca587a0f5ff480cc5867/Documentation/git-clone.txt#L185-L191","https://lore.kernel.org/git/xmqq4k14qe9g.fsf%40gitster.g/","https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations/","https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."}]},{"artifact":{"id":"67c221344b7c7cbd","cpes":["cpe:2.3:a:git-man:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git-man:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"git-man","purl":"pkg:deb/debian/git-man@1%3A2.47.3-0%2Bdeb13u1?arch=all&distro=debian-13.6&upstream=git","type":"deb","version":"1:2.47.3-0+deb13u1","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git-man/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/git-man/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git-man.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git-man.list"}],"upstreams":[{"name":"git"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-24975","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"git","version":"1:2.47.3-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2022-24975","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-08","epss":0.02624,"percentile":0.85025}],"risk":0.1312,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."},"relatedVulnerabilities":[{"id":"CVE-2022-24975","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-08","epss":0.02624,"percentile":0.85025}],"urls":["https://github.com/git/git/blob/2dc94da3744bfbbf145eca587a0f5ff480cc5867/Documentation/git-clone.txt#L185-L191","https://lore.kernel.org/git/xmqq4k14qe9g.fsf%40gitster.g/","https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations/","https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59995","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."},"relatedVulnerabilities":[{"id":"CVE-2026-59995","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59996","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."},"relatedVulnerabilities":[{"id":"CVE-2026-59996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-08","epss":0.0025,"percentile":0.15005}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"614dd2dfa62b9595","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.6&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap2/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libldap2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15719","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2020-15719","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-08","epss":0.02515,"percentile":0.84338}],"risk":0.12575,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."},"relatedVulnerabilities":[{"id":"CVE-2020-15719","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-08","epss":0.02515,"percentile":0.84338}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00033.html","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00059.html","https://access.redhat.com/errata/RHBA-2019:3674","https://bugs.openldap.org/show_bug.cgi?id=9266","https://bugzilla.redhat.com/show_bug.cgi?id=1740070","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."}]},{"artifact":{"id":"efad814c9c04e9fa","cpes":["cpe:2.3:a:golang:networking:v0.38.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.38.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.38.0","type":"go-module","version":"v0.38.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5030","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.38.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5030","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27136","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27136","date":"2026-10-08","epss":0.00223,"percentile":0.11872}],"risk":0.12376500000000001,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781685"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79575","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-27136","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27136","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27136","date":"2026-10-08","epss":0.00223,"percentile":0.11872}],"urls":["https://go.dev/cl/781685","https://go.dev/issue/79575","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5030"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27136","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"efad814c9c04e9fa","cpes":["cpe:2.3:a:golang:networking:v0.38.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.38.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.38.0","type":"go-module","version":"v0.38.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5027","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.38.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5027","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42502","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42502","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"risk":0.12376500000000001,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781701"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79572","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-42502","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42502","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42502","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"urls":["https://go.dev/cl/781701","https://go.dev/issue/79572","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5027"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42502","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"efad814c9c04e9fa","cpes":["cpe:2.3:a:golang:networking:v0.38.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.38.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.38.0","type":"go-module","version":"v0.38.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:vRMAPTMaeGqVhG5QyLJHqNDwecKTomGeqbnfZyKlBI8=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5029","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.38.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5029","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25681","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25681","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"risk":0.12376500000000001,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781703"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79574","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-25681","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25681","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25681","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"urls":["https://go.dev/cl/781703","https://go.dev/issue/79574","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5029"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25681","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-2243","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2007-2243","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-2243","cwe":"CWE-287","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2243","date":"2026-10-08","epss":0.02472,"percentile":0.84043}],"risk":0.12360000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-2243","description":"OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483."},"relatedVulnerabilities":[{"id":"CVE-2007-2243","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-2243","cwe":"CWE-287","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2243","date":"2026-10-08","epss":0.02472,"percentile":0.84043}],"urls":["http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053906.html","http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053951.html","http://securityreason.com/securityalert/2631","http://www.osvdb.org/34600","http://www.securityfocus.com/bid/23601","https://exchange.xforce.ibmcloud.com/vulnerabilities/33794","https://security.netapp.com/advisory/ntap-20191107-0003/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-2243","description":"OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received.  Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack.  CWE: CWE-440: Expected Behavior Violation   Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack.  If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed.  The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC.  FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received.  Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack.  CWE: CWE-440: Expected Behavior Violation   Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack.  If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed.  The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC.  FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received.  Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack.  CWE: CWE-440: Expected Behavior Violation   Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack.  If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed.  The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC.  FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"15791da16e435065","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"229bfebd2f7fc7f3","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"82f554653d484779","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"fb348d32a9e96833","cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"a8b3fa3699849e35","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"a8a27df4740c7b35","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"dd4a8fd9dddb7191","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:4.16.0-2+really2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"0875fd1d871c7e1b","cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"afc98bf002d364bb","cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.6","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59999","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"risk":0.11925,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."},"relatedVulnerabilities":[{"id":"CVE-2026-59999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-08","epss":0.00159,"percentile":0.04481}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."}]},{"artifact":{"id":"0c6f9f8288843347","cpes":["cpe:2.3:a:golang:text:v0.23.0:*:*:*:*:*:*:*"],"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.23.0","type":"go-module","version":"v0.23.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:D71I7dUrlY+VX0gQShAThNGHFxZ13dGLBHQLVl1mJlY=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.41.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6629","versionConstraint":"<0.41.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/text","version":"v0.23.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6629","fix":{"state":"fixed","versions":["0.41.0"],"available":[{"date":"2026-08-11","kind":"release","version":"0.41.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56851","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56851","date":"2026-10-08","epss":0.00155,"percentile":0.04088}],"risk":0.11624999999999999,"urls":["https://go.dev/issue/80112"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/793360","description":"The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-56851","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56851","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56851","date":"2026-10-08","epss":0.00155,"percentile":0.04088}],"urls":["https://go.dev/cl/793360","https://go.dev/issue/80112","https://pkg.go.dev/vuln/GO-2026-6629"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56851","description":"The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.   Impact summary: The NULL pointer dereference happens on a read which  leads to a crash and a Denial of Service for the affected client application.  CWE: CWE-476: NULL-pointer dereference  Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.  A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.  The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.  FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.   Impact summary: The NULL pointer dereference happens on a read which  leads to a crash and a Denial of Service for the affected client application.  CWE: CWE-476: NULL-pointer dereference  Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.  A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.  The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.  FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.   Impact summary: The NULL pointer dereference happens on a read which  leads to a crash and a Denial of Service for the affected client application.  CWE: CWE-476: NULL-pointer dereference  Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.  A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.  The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.  FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"21af26782f8669a0","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/debian/libp11-kit0@0.25.5-3?arch=amd64&distro=debian-13.6&upstream=p11-kit","type":"deb","version":"0.25.5-3","language":"","licenses":["Apache-2.0","BSD-3-clause","FSFAP","FSFULLR","GPL-2+","GPL-3+","ISC","LGPL-2.1","LGPL-2.1+","X11","customFSFUL","customFSFULLRWD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13757","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"p11-kit","version":"0.25.5-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13757","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-08","epss":0.00202,"percentile":0.09262}],"risk":0.11312000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."},"relatedVulnerabilities":[{"id":"CVE-2026-13757","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-08","epss":0.00202,"percentile":0.09262}],"urls":["https://access.redhat.com/errata/RHSA-2026:37469","https://access.redhat.com/errata/RHSA-2026:38342","https://access.redhat.com/errata/RHSA-2026:49667","https://access.redhat.com/errata/RHSA-2026:49668","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54387","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2026-13757","https://bugzilla.redhat.com/show_bug.cgi?id=2494556","https://github.com/advisories/GHSA-p2wm-69qx-x25w"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."}]},{"artifact":{"id":"0af6f2d3417a318d","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-2\\+b1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/debian/libacl1@2.3.2-2%2Bb1?arch=amd64&distro=debian-13.6&upstream=acl%402.3.2-2","type":"deb","version":"2.3.2-2+b1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl","version":"2.3.2-2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"acl","version":"2.3.2-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.11168999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"15791da16e435065","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"229bfebd2f7fc7f3","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"82f554653d484779","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"fb348d32a9e96833","cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"a8b3fa3699849e35","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"a8a27df4740c7b35","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"dd4a8fd9dddb7191","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:4.16.0-2+really2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"0875fd1d871c7e1b","cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"afc98bf002d364bb","cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.6","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106585","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106585","cwe":"CWE-409","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106585","date":"2026-10-08","epss":0.00189,"percentile":0.07871}],"risk":0.10867499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106585","description":"In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data."},"relatedVulnerabilities":[{"id":"CVE-2026-106585","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106585","cwe":"CWE-409","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106585","date":"2026-10-08","epss":0.00189,"percentile":0.07871}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106585","description":"In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data."}]},{"artifact":{"id":"5e92736840e45ef8","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.2-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.2-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=expat","type":"deb","version":"2.8.2-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.3-1~deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72522","versionConstraint":"< 2.8.3-1~deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"expat","version":"2.8.2-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-72522","fix":{"state":"fixed","versions":["2.8.3-1~deb13u1"],"available":[{"date":"2026-08-18","kind":"advisory","version":"2.8.3-1~deb13u1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72522","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-72522","date":"2026-10-08","epss":0.00191,"percentile":0.08042}],"risk":0.10696000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6446-1","link":"https://security-tracker.debian.org/tracker/DSA-6446-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72522","description":"libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions."},"relatedVulnerabilities":[{"id":"CVE-2026-72522","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72522","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-72522","date":"2026-10-08","epss":0.00191,"percentile":0.08042}],"urls":["https://bugzilla.mozilla.org/show_bug.cgi?id=2053153","https://github.com/libexpat/libexpat/pull/1296","http://www.openwall.com/lists/oss-security/2026/08/11/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72522","description":"libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions."}]},{"artifact":{"id":"5e92736840e45ef8","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.2-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.2-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=expat","type":"deb","version":"2.8.2-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"expat","version":"2.8.2-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"risk":0.106575,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59998","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."},"relatedVulnerabilities":[{"id":"CVE-2026-59998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-08","epss":0.0018,"percentile":0.06887}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2020-14145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-14145","date":"2026-10-08","epss":0.02057,"percentile":0.80701}],"risk":0.10285000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-14145","description":"The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected."},"relatedVulnerabilities":[{"id":"CVE-2020-14145","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-14145","date":"2026-10-08","epss":0.02057,"percentile":0.80701}],"urls":["http://www.openwall.com/lists/oss-security/2020/12/02/1","https://anongit.mindrot.org/openssh.git/commit/?id=b3855ff053f5078ec3d3c653cdaedefaa5fc362d","https://docs.ssh-mitm.at/CVE-2020-14145.html","https://github.com/openssh/openssh-portable/compare/V_8_3_P1...V_8_4_P1","https://github.com/ssh-mitm/ssh-mitm/blob/master/ssh_proxy_server/plugins/session/cve202014145.py","https://security.gentoo.org/glsa/202105-35","https://security.netapp.com/advisory/ntap-20200709-0004/","https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2-ausnutzung-eines-informationslecks-fuer-gezielte-mitm-angriffe-auf-ssh-clients/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14145","description":"The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected."}]},{"artifact":{"id":"daa1f8dfeee1793b","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"c5f7e9443917908e","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"0d7d9accbe1a77b1","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"dcbb71b238b6d3d6","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"6f2066ac1c2128fd","cpes":["cpe:2.3:a:libattr1:libattr1:1\\:2.5.2-3:*:*:*:*:*:*:*"],"name":"libattr1","purl":"pkg:deb/debian/libattr1@1%3A2.5.2-3?arch=amd64&distro=debian-13.6&upstream=attr","type":"deb","version":"1:2.5.2-3","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libattr1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libattr1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libattr1:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libattr1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"attr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"attr","version":"1:2.5.2-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54371","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-08","epss":0.00179,"percentile":0.06854}],"risk":0.10113499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54371","description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path."},"relatedVulnerabilities":[{"id":"CVE-2026-54371","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-08","epss":0.00179,"percentile":0.06854}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f","https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b","https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr","https://access.redhat.com/errata/RHSA-2026:34889","https://access.redhat.com/errata/RHSA-2026:56133","https://access.redhat.com/errata/RHSA-2026:59380","https://access.redhat.com/errata/RHSA-2026:60226","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/security/cve/CVE-2026-54371","https://bugzilla.redhat.com/show_bug.cgi?id=2490283","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54371","description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path."}]},{"artifact":{"id":"8a1ec6d9372df578","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.6&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27171","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"risk":0.10027499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."},"relatedVulnerabilities":[{"id":"CVE-2026-27171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms.  Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar.  CWE: CWE-208: Observable Timing Discrepancy  Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel.  FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module.  OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.  This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov.  -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov"},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms.  Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar.  CWE: CWE-208: Observable Timing Discrepancy  Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel.  FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module.  OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.  This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov.  -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov"},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms.  Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar.  CWE: CWE-208: Observable Timing Discrepancy  Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel.  FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module.  OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.  This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov.  -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov"},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"c8ce23e36f4d6bca","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=pcre2","type":"deb","version":"10.46-1~deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"fix":{"suggestedVersion":"10.46-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"< 10.46-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pcre2","version":"10.46-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"fixed","versions":["10.46-1~deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"10.46-1~deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.09639,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"7402a3d31bb024db","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64&distro=debian-13.6&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"3f9378db54aaac9e","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all&distro=debian-13.6&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"e96cb50e09a471e0","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64&distro=debian-13.6&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4869","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4869","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"risk":0.09555000000000001,"urls":["https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763766","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."},"relatedVulnerabilities":[{"id":"CVE-2026-32288","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"urls":["https://go.dev/cl/763766","https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4869"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32288","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."}]},{"artifact":{"id":"fcb706650c034eda","cpes":["cpe:2.3:a:libfreetype6:libfreetype6:2.13.3\\+dfsg-1\\+deb13u1:*:*:*:*:*:*:*"],"name":"libfreetype6","purl":"pkg:deb/debian/libfreetype6@2.13.3%2Bdfsg-1%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=freetype","type":"deb","version":"2.13.3+dfsg-1+deb13u1","language":"","licenses":["BSD-3-Clause","BSL-1.0","Expat","FSFAP","FTL","GPL-2","GPL-2+","GPL-3","GPL-3+","MIT-Modern-Variant","MIT-SMC","OpenGroup-MIT","Public-Domain","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfreetype6/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libfreetype6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"freetype"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95512","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"freetype","version":"2.13.3+dfsg-1+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95512","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"risk":0.09135,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95512","description":"A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate."},"relatedVulnerabilities":[{"id":"CVE-2026-95512","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"urls":["https://access.redhat.com/errata/RHSA-2026:74952","https://access.redhat.com/security/cve/CVE-2026-95512","https://bugzilla.redhat.com/show_bug.cgi?id=2462295","https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95512","description":"A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59997","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."},"relatedVulnerabilities":[{"id":"CVE-2026-59997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-08","epss":0.00175,"percentile":0.06327}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."}]},{"artifact":{"id":"6004b03bf692a003","cpes":["cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2-1.0:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*"],"name":"libbz2-1.0","purl":"pkg:deb/debian/libbz2-1.0@1.0.8-6?arch=amd64&distro=debian-13.6&upstream=bzip2","type":"deb","version":"1.0.8-6","language":"","licenses":["BSD-variant","GPL-2"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbz2-1.0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libbz2-1.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bzip2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"bzip2","version":"1.0.8-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42250","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"risk":0.08918,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).  This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"},"relatedVulnerabilities":[{"id":"CVE-2026-42250","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.  Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.  The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.  Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.  The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.  FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.  Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.  The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.  Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.  The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.  FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.  Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.  The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.  Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.  The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.  FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"15791da16e435065","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"229bfebd2f7fc7f3","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"82f554653d484779","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"fb348d32a9e96833","cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"a8b3fa3699849e35","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"a8a27df4740c7b35","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"dd4a8fd9dddb7191","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:4.16.0-2+really2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"0875fd1d871c7e1b","cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"afc98bf002d364bb","cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.6","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.08652000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"21af26782f8669a0","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/debian/libp11-kit0@0.25.5-3?arch=amd64&distro=debian-13.6&upstream=p11-kit","type":"deb","version":"0.25.5-3","language":"","licenses":["Apache-2.0","BSD-3-clause","FSFAP","FSFULLR","GPL-2+","GPL-3+","ISC","LGPL-2.1","LGPL-2.1+","X11","customFSFUL","customFSFULLRWD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18938","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"p11-kit","version":"0.25.5-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18938","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18938","date":"2026-10-08","epss":0.00152,"percentile":0.03827}],"risk":0.08512000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18938","description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems."},"relatedVulnerabilities":[{"id":"CVE-2026-18938","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18938","date":"2026-10-08","epss":0.00152,"percentile":0.03827}],"urls":["https://access.redhat.com/security/cve/CVE-2026-18938","https://bugzilla.redhat.com/show_bug.cgi?id=2478995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18938","description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems."}]},{"artifact":{"id":"0e674e420f2bfafa","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=sqlite3","type":"deb","version":"3.46.1-7+deb13u1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-50812","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-50812","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50812","date":"2026-10-08","epss":0.0016,"percentile":0.04607}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50812","description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer."},"relatedVulnerabilities":[{"id":"CVE-2026-50812","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50812","date":"2026-10-08","epss":0.0016,"percentile":0.04607}],"urls":["https://gist.github.com/junius-sec/bb556f333957c5226dede314db0e9e91","https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d","https://sqlite.org/src/info/e807d4e3798efd53"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50812","description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer."}]},{"artifact":{"id":"8bfae933fd40ea5d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=systemd","type":"deb","version":"257.13-1~deb13u1","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"4468281f476fc994","cpes":["cpe:2.3:a:libudev1:libudev1:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=systemd","type":"deb","version":"257.13-1~deb13u1","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"0e674e420f2bfafa","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=sqlite3","type":"deb","version":"3.46.1-7+deb13u1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-50813","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-50813","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50813","cwe":"CWE-126","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50813","date":"2026-10-08","epss":0.00159,"percentile":0.04405}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50813","description":"An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path"},"relatedVulnerabilities":[{"id":"CVE-2026-50813","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50813","cwe":"CWE-126","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50813","date":"2026-10-08","epss":0.00159,"percentile":0.04405}],"urls":["https://gist.github.com/junius-sec/f8acb66bafb80134c8e1a1c8c7c9f4f4","https://github.com/sqlite/sqlite/commit/c597ed79d1bd03f57198d10d1f431adda293cf2e","https://sqlite.org/src/info/869a51ae84df"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50813","description":"An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path"}]},{"artifact":{"id":"5e92736840e45ef8","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.2-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.2-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=expat","type":"deb","version":"2.8.2-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76957","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"expat","version":"2.8.2-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76957","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76957","date":"2026-10-08","epss":0.00107,"percentile":0.01051}],"risk":0.081855,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76957","description":"libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412."},"relatedVulnerabilities":[{"id":"CVE-2026-76957","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76957","date":"2026-10-08","epss":0.00107,"percentile":0.01051}],"urls":["https://github.com/libexpat/libexpat/pull/1322","https://github.com/libexpat/libexpat/pull/1329"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76957","description":"libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412."}]},{"artifact":{"id":"0af6f2d3417a318d","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-2\\+b1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/debian/libacl1@2.3.2-2%2Bb1?arch=amd64&distro=debian-13.6&upstream=acl%402.3.2-2","type":"deb","version":"2.3.2-2+b1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl","version":"2.3.2-2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"acl","version":"2.3.2-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54370","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"risk":0.081585,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-54370","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."}]},{"artifact":{"id":"b53f18d1bacb9feb","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.  Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.  Applications performing SM2 signature generation are affected on all platforms.  FIPS Impact: no SM2 is not a FIPS algorithm."},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"f6113e6cdbf866f3","cpes":["cpe:2.3:a:openssl:openssl:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.  Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.  Applications performing SM2 signature generation are affected on all platforms.  FIPS Impact: no SM2 is not a FIPS algorithm."},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"3278b1eea0a38ab7","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.6-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.6-1~deb13u2?arch=amd64&distro=debian-13.6&upstream=openssl","type":"deb","version":"3.5.6-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssl","version":"3.5.6-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.  Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.  Applications performing SM2 signature generation are affected on all platforms.  FIPS Impact: no SM2 is not a FIPS algorithm."},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"0e674e420f2bfafa","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=sqlite3","type":"deb","version":"3.46.1-7+deb13u1","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-45346","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2021-45346","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-45346","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-45346","date":"2026-10-08","epss":0.01614,"percentile":0.75265}],"risk":0.08070000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-45346","description":"A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect."},"relatedVulnerabilities":[{"id":"CVE-2021-45346","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-45346","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-45346","date":"2026-10-08","epss":0.01614,"percentile":0.75265}],"urls":["https://github.com/guyinatuxedo/sqlite3_record_leaking","https://security.netapp.com/advisory/ntap-20220303-0001/","https://sqlite.org/forum/forumpost/056d557c2f8c452ed5","https://sqlite.org/forum/forumpost/53de8864ba114bf6","https://www.sqlite.org/cves.html#status_of_recent_sqlite_cves"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-45346","description":"A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73282","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73282","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"risk":0.07987,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73282","description":"In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent."},"relatedVulnerabilities":[{"id":"CVE-2026-73282","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73282","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73282","date":"2026-10-08","epss":0.00163,"percentile":0.04988}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73282","description":"In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.    This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.    This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.07005999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.  Exploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.07005999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.  Exploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"b30644f429eabdac","cpes":["cpe:2.3:a:gzip:gzip:1.13-1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/debian/gzip@1.13-1?arch=amd64&distro=debian-13.6","type":"deb","version":"1.13-1","language":"","licenses":["FSF-manpages","GFDL-1.3+-no-invariant","GFDL-3","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/gzip.list"},{"path":"/var/lib/dpkg/info/gzip.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/gzip.postinst"},{"path":"/var/lib/dpkg/info/gzip.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/gzip.preinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.13-1+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41991","versionConstraint":"< 1.13-1+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"gzip","version":"1.13-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-41991","fix":{"state":"fixed","versions":["1.13-1+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.13-1+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41991","cwe":"CWE-377","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41991","date":"2026-10-08","epss":0.00142,"percentile":0.02987}],"risk":0.06887,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41991","description":"GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.  This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269"},"relatedVulnerabilities":[{"id":"CVE-2026-41991","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41991","cwe":"CWE-377","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41991","date":"2026-10-08","epss":0.00142,"percentile":0.02987}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269","https://www.gnu.org/software/gzip/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41991","description":"GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.\n\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269"}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15649","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"risk":0.066675,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."},"relatedVulnerabilities":[{"id":"CVE-2025-15649","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15649","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"risk":0.066675,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."},"relatedVulnerabilities":[{"id":"CVE-2025-15649","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15649","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"risk":0.066675,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."},"relatedVulnerabilities":[{"id":"CVE-2025-15649","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.40.1-6+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"< 5.40.1-6+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15649","fix":{"state":"fixed","versions":["5.40.1-6+deb13u1"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"5.40.1-6+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"risk":0.066675,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.  _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.  The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."},"relatedVulnerabilities":[{"id":"CVE-2025-15649","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."}]},{"artifact":{"id":"213d133cc46bf69b","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.6","type":"deb","version":"1.35+dfsg-3.1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18508","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"risk":0.06627,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."},"relatedVulnerabilities":[{"id":"CVE-2026-18508","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106582","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106582","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106582","cwe":"CWE-514","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106582","date":"2026-10-08","epss":0.00182,"percentile":0.07148}],"risk":0.06096999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106582","description":"In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 \"Crossing the Streams\" findings."},"relatedVulnerabilities":[{"id":"CVE-2026-106582","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106582","cwe":"CWE-514","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106582","date":"2026-10-08","epss":0.00182,"percentile":0.07148}],"urls":["https://arxiv.org/abs/2609.07709","https://www.openssh.org/releasenotes.html#10.6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106582","description":"In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 \"Crossing the Streams\" findings."}]},{"artifact":{"id":"0ea1a43670a5d18e","cpes":["cpe:2.3:a:apt:apt:3.0.3:*:*:*:*:*:*:*"],"name":"apt","purl":"pkg:deb/debian/apt@3.0.3?arch=amd64&distro=debian-13.6","type":"deb","version":"3.0.3","language":"","licenses":["BSD-3-clause","Expat","GPL-2","GPL-2+","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apt/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/apt/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/apt.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/apt.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apt.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/apt.list"},{"path":"/var/lib/dpkg/info/apt.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/apt.postinst"},{"path":"/var/lib/dpkg/info/apt.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/apt.postrm"},{"path":"/var/lib/dpkg/info/apt.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/apt.preinst"},{"path":"/var/lib/dpkg/info/apt.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/apt.prerm"},{"path":"/var/lib/dpkg/info/apt.shlibs","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/apt.shlibs"},{"path":"/var/lib/dpkg/info/apt.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/apt.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2011-3374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"apt","version":"3.0.3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2011-3374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3374","date":"2026-10-08","epss":0.01191,"percentile":0.6706}],"risk":0.05955000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3374","description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3374","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3374","date":"2026-10-08","epss":0.01191,"percentile":0.6706}],"urls":["https://access.redhat.com/security/cve/cve-2011-3374","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642480","https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.html","https://seclists.org/fulldisclosure/2011/Sep/221","https://security-tracker.debian.org/tracker/CVE-2011-3374","https://snyk.io/vuln/SNYK-LINUX-APT-116518","https://ubuntu.com/security/CVE-2011-3374"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3374","description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack."}]},{"artifact":{"id":"25f4161ec6258e4d","cpes":["cpe:2.3:a:libapt-pkg7.0:libapt-pkg7.0:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:libapt-pkg7.0:libapt_pkg7.0:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg7.0:libapt-pkg7.0:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:libapt_pkg7.0:libapt_pkg7.0:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt-pkg7.0:3.0.3:*:*:*:*:*:*:*","cpe:2.3:a:libapt:libapt_pkg7.0:3.0.3:*:*:*:*:*:*:*"],"name":"libapt-pkg7.0","purl":"pkg:deb/debian/libapt-pkg7.0@3.0.3?arch=amd64&distro=debian-13.6&upstream=apt","type":"deb","version":"3.0.3","language":"","licenses":["BSD-3-clause","Expat","GPL-2","GPL-2+","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libapt-pkg7.0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libapt-pkg7.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libapt-pkg7.0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libapt-pkg7.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"apt"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-3374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"apt","version":"3.0.3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2011-3374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3374","date":"2026-10-08","epss":0.01191,"percentile":0.6706}],"risk":0.05955000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3374","description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3374","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3374","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3374","date":"2026-10-08","epss":0.01191,"percentile":0.6706}],"urls":["https://access.redhat.com/security/cve/cve-2011-3374","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642480","https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.html","https://seclists.org/fulldisclosure/2011/Sep/221","https://security-tracker.debian.org/tracker/CVE-2011-3374","https://snyk.io/vuln/SNYK-LINUX-APT-116518","https://ubuntu.com/security/CVE-2011-3374"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3374","description":"It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack."}]},{"artifact":{"id":"15791da16e435065","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41-5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"229bfebd2f7fc7f3","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41-5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"82f554653d484779","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41-5:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"fb348d32a9e96833","cpes":["cpe:2.3:a:libmount1:libmount1:2.41-5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"a8b3fa3699849e35","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41-5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"a8a27df4740c7b35","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41-5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"dd4a8fd9dddb7191","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41-5:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux%402.41-5","type":"deb","version":"1:4.16.0-2+really2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41-5"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"0875fd1d871c7e1b","cpes":["cpe:2.3:a:mount:mount:2.41-5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41-5?arch=amd64&distro=debian-13.6&upstream=util-linux","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"afc98bf002d364bb","cpes":["cpe:2.3:a:util-linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41-5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41-5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41-5?arch=amd64&distro=debian-13.6","type":"deb","version":"2.41-5","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.41.5-0+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.41.5-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"util-linux","version":"2.41-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.41.5-0+deb13u1"],"available":[{"date":"2026-08-14","kind":"advisory","version":"2.41.5-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6442-1","link":"https://security-tracker.debian.org/tracker/DSA-6442-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"daa1f8dfeee1793b","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"c5f7e9443917908e","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"0d7d9accbe1a77b1","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"dcbb71b238b6d3d6","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-08","epss":0.01128,"percentile":0.65338}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"8e03bdf0d5ec8f50","cpes":["cpe:2.3:a:git:git:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"git","purl":"pkg:deb/debian/git@1%3A2.47.3-0%2Bdeb13u1?arch=amd64&distro=debian-13.6","type":"deb","version":"1:2.47.3-0+deb13u1","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/git/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.list"},{"path":"/var/lib/dpkg/info/git.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.postinst"},{"path":"/var/lib/dpkg/info/git.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.postrm"},{"path":"/var/lib/dpkg/info/git.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.preinst"},{"path":"/var/lib/dpkg/info/git.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1000021","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"git","version":"1:2.47.3-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-1000021","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000021","date":"2026-10-08","epss":0.01074,"percentile":0.63912}],"risk":0.053700000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-1000021","description":"GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack)."},"relatedVulnerabilities":[{"id":"CVE-2018-1000021","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000021","date":"2026-10-08","epss":0.01074,"percentile":0.63912}],"urls":["http://www.batterystapl.es/2018/01/security-implications-of-ansi-escape.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000021","description":"GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack)."}]},{"artifact":{"id":"67c221344b7c7cbd","cpes":["cpe:2.3:a:git-man:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git-man:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"git-man","purl":"pkg:deb/debian/git-man@1%3A2.47.3-0%2Bdeb13u1?arch=all&distro=debian-13.6&upstream=git","type":"deb","version":"1:2.47.3-0+deb13u1","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git-man/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/git-man/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git-man.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git-man.list"}],"upstreams":[{"name":"git"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-1000021","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"git","version":"1:2.47.3-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-1000021","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000021","date":"2026-10-08","epss":0.01074,"percentile":0.63912}],"risk":0.053700000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-1000021","description":"GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack)."},"relatedVulnerabilities":[{"id":"CVE-2018-1000021","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000021","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000021","date":"2026-10-08","epss":0.01074,"percentile":0.63912}],"urls":["http://www.batterystapl.es/2018/01/security-implications-of-ansi-escape.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000021","description":"GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack)."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73281","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73281","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"risk":0.05134999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73281","description":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension."},"relatedVulnerabilities":[{"id":"CVE-2026-73281","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73281","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-73281","date":"2026-10-08","epss":0.00158,"percentile":0.04376}],"urls":["https://www.openssh.org/releasenotes.html#10.5"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73281","description":"In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension."}]},{"artifact":{"id":"11db3883d0a8f153","cpes":["cpe:2.3:a:golang:x\\/sys:v0.31.0:*:*:*:*:*:*:*"],"name":"golang.org/x/sys","purl":"pkg:golang/golang.org/x/sys@v0.31.0","type":"go-module","version":"v0.31.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ioabZlmFYtWhL+TRYpcnNlLwhyxaM9kWTDEmfnprqik=","mainModule":"github.com/git-lfs/git-lfs/v3","architecture":"amd64","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.44.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5024","versionConstraint":"<0.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/sys","version":"v0.31.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5024","fix":{"state":"fixed","versions":["0.44.0"],"available":[{"date":"2026-04-23","kind":"release","version":"0.44.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"risk":0.04976999999999999,"urls":["https://go.dev/cl/770080","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78916","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."},"relatedVulnerabilities":[{"id":"CVE-2026-39824","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"urls":["https://go.dev/cl/770080","https://go.dev/issue/78916","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg","https://pkg.go.dev/vuln/GO-2026-5024"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39824","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."}]},{"artifact":{"id":"c8ce23e36f4d6bca","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=pcre2","type":"deb","version":"10.46-1~deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"fix":{"suggestedVersion":"10.46-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"< 10.46-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"pcre2","version":"10.46-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89162","fix":{"state":"fixed","versions":["10.46-1~deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"10.46-1~deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"risk":0.04913999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."},"relatedVulnerabilities":[{"id":"CVE-2026-89162","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."}]},{"artifact":{"id":"893ab677af71bedc","cpes":["cpe:2.3:a:login.defs:login.defs:1\\:4.17.4-2:*:*:*:*:*:*:*"],"name":"login.defs","purl":"pkg:deb/debian/login.defs@1%3A4.17.4-2?arch=all&distro=debian-13.6&upstream=shadow","type":"deb","version":"1:4.17.4-2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login.defs/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/login.defs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/login.defs.postinst"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-5686","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2007-5686","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-5686","date":"2026-10-08","epss":0.00942,"percentile":0.59797}],"risk":0.0471,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-5686","description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers."},"relatedVulnerabilities":[{"id":"CVE-2007-5686","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:N/A:N","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-5686","date":"2026-10-08","epss":0.00942,"percentile":0.59797}],"urls":["http://secunia.com/advisories/27215","http://www.securityfocus.com/archive/1/482129/100/100/threaded","http://www.securityfocus.com/archive/1/482857/100/0/threaded","http://www.securityfocus.com/bid/26048","http://www.vupen.com/english/advisories/2007/3474","https://issues.rpath.com/browse/RPL-1825"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-5686","description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers."}]},{"artifact":{"id":"a0c2eaa9ca5431ff","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.17.4-2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/debian/passwd@1%3A4.17.4-2?arch=amd64&distro=debian-13.6&upstream=shadow","type":"deb","version":"1:4.17.4-2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-5686","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2007-5686","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-5686","date":"2026-10-08","epss":0.00942,"percentile":0.59797}],"risk":0.0471,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-5686","description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers."},"relatedVulnerabilities":[{"id":"CVE-2007-5686","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:N/A:N","metrics":{"baseScore":4.9,"impactScore":6.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-5686","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-5686","date":"2026-10-08","epss":0.00942,"percentile":0.59797}],"urls":["http://secunia.com/advisories/27215","http://www.securityfocus.com/archive/1/482129/100/100/threaded","http://www.securityfocus.com/archive/1/482857/100/0/threaded","http://www.securityfocus.com/bid/26048","http://www.vupen.com/english/advisories/2007/3474","https://issues.rpath.com/browse/RPL-1825"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-5686","description":"initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts.  NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers."}]},{"artifact":{"id":"8bfae933fd40ea5d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=systemd","type":"deb","version":"257.13-1~deb13u1","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.04378499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"4468281f476fc994","cpes":["cpe:2.3:a:libudev1:libudev1:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=systemd","type":"deb","version":"257.13-1~deb13u1","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.04378499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.04257,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.  When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.04257,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.  When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"daa1f8dfeee1793b","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"c5f7e9443917908e","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"0d7d9accbe1a77b1","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"dcbb71b238b6d3d6","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.6&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-08","epss":0.00815,"percentile":0.55761}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"213d133cc46bf69b","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.6","type":"deb","version":"1.35+dfsg-3.1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18477","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"risk":0.0376,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."},"relatedVulnerabilities":[{"id":"CVE-2026-18477","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"urls":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}]},{"artifact":{"id":"ca88752821693d8d","cpes":["cpe:2.3:a:patch:patch:2.8-2:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.8-2?arch=amd64&distro=debian-13.6","type":"deb","version":"2.8-2","language":"","licenses":["GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-45261","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"patch","version":"2.8-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2021-45261","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-45261","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-45261","date":"2026-10-08","epss":0.00705,"percentile":0.5191}],"risk":0.035250000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-45261","description":"An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service."},"relatedVulnerabilities":[{"id":"CVE-2021-45261","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-45261","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-45261","date":"2026-10-08","epss":0.00705,"percentile":0.5191}],"urls":["https://savannah.gnu.org/bugs/?61685"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-45261","description":"An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106583","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106583","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106583","cwe":"CWE-99","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106583","date":"2026-10-08","epss":0.00128,"percentile":0.02119}],"risk":0.0352,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106583","description":"In ssh in OpenSSH before 10.6, a $ or \\ character can occur in a command-line username, leading to injection."},"relatedVulnerabilities":[{"id":"CVE-2026-106583","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106583","cwe":"CWE-99","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106583","date":"2026-10-08","epss":0.00128,"percentile":0.02119}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106583","description":"In ssh in OpenSSH before 10.6, a $ or \\ character can occur in a command-line username, leading to injection."}]},{"artifact":{"id":"8bfae933fd40ea5d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=systemd","type":"deb","version":"257.13-1~deb13u1","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-16742","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"risk":0.03334499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"},"relatedVulnerabilities":[{"id":"CVE-2026-16742","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"}]},{"artifact":{"id":"4468281f476fc994","cpes":["cpe:2.3:a:libudev1:libudev1:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64&distro=debian-13.6&upstream=systemd","type":"deb","version":"257.13-1~deb13u1","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-16742","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"risk":0.03334499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"},"relatedVulnerabilities":[{"id":"CVE-2026-16742","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"}]},{"artifact":{"id":"768dfbdcd0e8ec01","cpes":["cpe:2.3:a:golang:go:1.25.3:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.3","type":"go-module","version":"go1.25.3","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.3"},"locations":[{"path":"/usr/local/bin/git-lfs","layerID":"sha256:56dd00ba72e002299bb18e2d9cbbecf8579534519c6cb90b6d4ce1e2e086c69f","accessPath":"/usr/local/bin/git-lfs","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4602","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.3"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4602","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"risk":0.03245,"urls":["https://go.dev/issue/77827","https://go.dev/cl/749480"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened.\n\nThe impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."},"relatedVulnerabilities":[{"id":"CVE-2026-27139","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"urls":["https://go.dev/cl/749480","https://go.dev/issue/77827","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4602"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27139","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."}]},{"artifact":{"id":"042b1fb7243a134f","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15079","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"risk":0.0275,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file."},"relatedVulnerabilities":[{"id":"CVE-2025-15079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file."}]},{"artifact":{"id":"b04fc0af73b95d8c","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15079","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"risk":0.0275,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file."},"relatedVulnerabilities":[{"id":"CVE-2025-15079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file."}]},{"artifact":{"id":"88034aca81b68a91","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u4:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u4?arch=amd64&distro=debian-13.6&upstream=curl","type":"deb","version":"8.14.1-2+deb13u4","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"curl","version":"8.14.1-2+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15079","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"risk":0.0275,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file."},"relatedVulnerabilities":[{"id":"CVE-2025-15079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file."}]},{"artifact":{"id":"db8f902611567c92","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.027285,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"396f0047ff1f6fad","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u3:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u3?arch=amd64&distro=debian-13.6&upstream=glibc","type":"deb","version":"2.41-12+deb13u3","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"glibc","version":"2.41-12+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.027285,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"7da008112faf0691","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-4116","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2011-4116","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4116","date":"2026-10-08","epss":0.00524,"percentile":0.42672}],"risk":0.0262,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4116","description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks."},"relatedVulnerabilities":[{"id":"CVE-2011-4116","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:S/C:N/I:P/A:N","metrics":{"baseScore":1.5,"impactScore":2.9,"exploitabilityScore":2.7},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4116","date":"2026-10-08","epss":0.00524,"percentile":0.42672}],"urls":["http://www.openwall.com/lists/oss-security/2011/11/04/2","http://www.openwall.com/lists/oss-security/2011/11/04/4","https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14","https://rt.cpan.org/Public/Bug/Display.html?id=69106","https://seclists.org/oss-sec/2011/q4/238"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4116","description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks."}]},{"artifact":{"id":"31ca1b2415b0d14d","cpes":["cpe:2.3:a:perl:perl:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6?arch=amd64&distro=debian-13.6","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2011-4116","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2011-4116","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4116","date":"2026-10-08","epss":0.00524,"percentile":0.42672}],"risk":0.0262,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4116","description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks."},"relatedVulnerabilities":[{"id":"CVE-2011-4116","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:S/C:N/I:P/A:N","metrics":{"baseScore":1.5,"impactScore":2.9,"exploitabilityScore":2.7},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4116","date":"2026-10-08","epss":0.00524,"percentile":0.42672}],"urls":["http://www.openwall.com/lists/oss-security/2011/11/04/2","http://www.openwall.com/lists/oss-security/2011/11/04/4","https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14","https://rt.cpan.org/Public/Bug/Display.html?id=69106","https://seclists.org/oss-sec/2011/q4/238"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4116","description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks."}]},{"artifact":{"id":"c9a7a6c12ce9a73e","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:6f94328331290cbd81edab450664d42da7b64c191416c9346cd5d28c84f76035","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-4116","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2011-4116","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4116","date":"2026-10-08","epss":0.00524,"percentile":0.42672}],"risk":0.0262,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4116","description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks."},"relatedVulnerabilities":[{"id":"CVE-2011-4116","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:S/C:N/I:P/A:N","metrics":{"baseScore":1.5,"impactScore":2.9,"exploitabilityScore":2.7},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4116","date":"2026-10-08","epss":0.00524,"percentile":0.42672}],"urls":["http://www.openwall.com/lists/oss-security/2011/11/04/2","http://www.openwall.com/lists/oss-security/2011/11/04/4","https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14","https://rt.cpan.org/Public/Bug/Display.html?id=69106","https://seclists.org/oss-sec/2011/q4/238"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4116","description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks."}]},{"artifact":{"id":"2ddb516994b4c1cb","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6?arch=all&distro=debian-13.6&upstream=perl","type":"deb","version":"5.40.1-6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-4116","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"perl","version":"5.40.1-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2011-4116","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4116","date":"2026-10-08","epss":0.00524,"percentile":0.42672}],"risk":0.0262,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-4116","description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks."},"relatedVulnerabilities":[{"id":"CVE-2011-4116","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:S/C:N/I:P/A:N","metrics":{"baseScore":1.5,"impactScore":2.9,"exploitabilityScore":2.7},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-4116","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-4116","date":"2026-10-08","epss":0.00524,"percentile":0.42672}],"urls":["http://www.openwall.com/lists/oss-security/2011/11/04/2","http://www.openwall.com/lists/oss-security/2011/11/04/4","https://github.com/Perl-Toolchain-Gang/File-Temp/issues/14","https://rt.cpan.org/Public/Bug/Display.html?id=69106","https://seclists.org/oss-sec/2011/q4/238"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-4116","description":"_is_safe in the File::Temp module for Perl does not properly handle symlinks."}]},{"artifact":{"id":"f04491801b5f5c94","cpes":["cpe:2.3:a:libpng16-16t64:libpng16-16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16t64:libpng16_16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16-16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16_16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16t64:1.6.48-1\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpng16-16t64","purl":"pkg:deb/debian/libpng16-16t64@1.6.48-1%2Bdeb13u5?arch=amd64&distro=debian-13.6&upstream=libpng1.6","type":"deb","version":"1.6.48-1+deb13u5","language":"","licenses":["Apache-2.0","BSD-3-clause","BSD-like-with-advertising-clause","GPL-2","GPL-2+","expat","libpng"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpng16-16t64/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/libpng16-16t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libpng1.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-4214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"libpng1.6","version":"1.6.48-1+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2021-4214","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-4214","cwe":"CWE-120","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-4214","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-4214","date":"2026-10-08","epss":0.00522,"percentile":0.42457}],"risk":0.0261,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2021-4214","description":"A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2021-4214","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-4214","cwe":"CWE-120","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-4214","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-4214","date":"2026-10-08","epss":0.00522,"percentile":0.42457}],"urls":["https://access.redhat.com/security/cve/CVE-2021-4214","https://bugzilla.redhat.com/show_bug.cgi?id=2043393","https://github.com/glennrp/libpng/issues/302","https://security-tracker.debian.org/tracker/CVE-2021-4214","https://security.netapp.com/advisory/ntap-20221020-0001/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4214","description":"A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service."}]},{"artifact":{"id":"8e03bdf0d5ec8f50","cpes":["cpe:2.3:a:git:git:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"git","purl":"pkg:deb/debian/git@1%3A2.47.3-0%2Bdeb13u1?arch=amd64&distro=debian-13.6","type":"deb","version":"1:2.47.3-0+deb13u1","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/git/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.conffiles","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.list"},{"path":"/var/lib/dpkg/info/git.postinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.postinst"},{"path":"/var/lib/dpkg/info/git.postrm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.postrm"},{"path":"/var/lib/dpkg/info/git.preinst","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.preinst"},{"path":"/var/lib/dpkg/info/git.prerm","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-52005","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"git","version":"1:2.47.3-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52005","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-52005","cwe":"CWE-150","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-52005","date":"2026-10-08","epss":0.00513,"percentile":0.41827}],"risk":0.02565,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52005","description":"Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called \"sideband channel\". These messages will be prefixed with \"remote:\" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources."},"relatedVulnerabilities":[{"id":"CVE-2024-52005","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-52005","cwe":"CWE-150","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-52005","date":"2026-10-08","epss":0.00513,"percentile":0.41827}],"urls":["https://github.com/git/git/security/advisories/GHSA-7jjc-gg6m-3329","https://lore.kernel.org/git/1M9FnZ-1taoNo1wwh-00ESSd@mail.gmx.net"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52005","description":"Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called \"sideband channel\". These messages will be prefixed with \"remote:\" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources."}]},{"artifact":{"id":"67c221344b7c7cbd","cpes":["cpe:2.3:a:git-man:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git-man:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"git-man","purl":"pkg:deb/debian/git-man@1%3A2.47.3-0%2Bdeb13u1?arch=all&distro=debian-13.6&upstream=git","type":"deb","version":"1:2.47.3-0+deb13u1","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git-man/copyright","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/usr/share/doc/git-man/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.md5sums","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git-man.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.list","layerID":"sha256:8a74c822d08f9c32303e28e09c5ebe1c7cb7124f80653b9e7fee0bef0f89c12b","accessPath":"/var/lib/dpkg/info/git-man.list"}],"upstreams":[{"name":"git"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52005","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.6"},"package":{"name":"git","version":"1:2.47.3-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52005","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-52005","cwe":"CWE-150","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-52005","date":"2026-10-08","epss":0.00513,"percentile":0.41827}],"risk":0.02565,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52005","description":"Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called \"sideband channel\". These messages will be prefixed with \"remote:\" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources."},"relatedVulnerabilities":[{"id":"CVE-2024-52005","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52005","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2024-52005","cwe":"CWE-150","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-52005","date":"2026-10-08","epss":0.00513,"percentile":0.41827}],"urls":["https://github.com/git/git/security/advisories/GHSA-7jjc-gg6m-3329","https://lore.kernel.org/git/1M9FnZ-1taoNo1wwh-00ESSd@mail.gmx.net"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52005","description":"Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called \"sideband channel\". These messages will be prefixed with \"remote:\" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:26:33.441Z","grype_db_version":"2026-10-09T06:32:32.000Z"}