{"grype_matches":[{"artifact":{"id":"809ea4b423ef5f0e","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u4:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u4","language":"","licenses":["sha256:a07e99815cf1998f1dabbc21fe199460bfa09b85ead0d56b49a32cac3d1791b5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-3389","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2011-3389","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"risk":3.66635,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-08","epss":0.73327,"percentile":0.99453}],"urls":["http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/","http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx","http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx","http://curl.haxx.se/docs/adv_20120124B.html","http://downloads.asterisk.org/pub/security/AST-2016-001.html","http://ekoparty.org/2011/juliano-rizzo.php","http://eprint.iacr.org/2004/111","http://eprint.iacr.org/2006/136","http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html","http://isc.sans.edu/diary/SSL+TLS+part+3+/11635","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html","http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html","http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html","http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://marc.info/?l=bugtraq&m=132750579901589&w=2","http://marc.info/?l=bugtraq&m=132872385320240&w=2","http://marc.info/?l=bugtraq&m=133365109612558&w=2","http://marc.info/?l=bugtraq&m=133728004526190&w=2","http://marc.info/?l=bugtraq&m=134254866602253&w=2","http://marc.info/?l=bugtraq&m=134254957702612&w=2","http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue","http://osvdb.org/74829","http://rhn.redhat.com/errata/RHSA-2012-0508.html","http://rhn.redhat.com/errata/RHSA-2013-1455.html","http://secunia.com/advisories/45791","http://secunia.com/advisories/47998","http://secunia.com/advisories/48256","http://secunia.com/advisories/48692","http://secunia.com/advisories/48915","http://secunia.com/advisories/48948","http://secunia.com/advisories/49198","http://secunia.com/advisories/55322","http://secunia.com/advisories/55350","http://secunia.com/advisories/55351","http://security.gentoo.org/glsa/glsa-201203-02.xml","http://security.gentoo.org/glsa/glsa-201406-32.xml","http://support.apple.com/kb/HT4999","http://support.apple.com/kb/HT5001","http://support.apple.com/kb/HT5130","http://support.apple.com/kb/HT5281","http://support.apple.com/kb/HT5501","http://support.apple.com/kb/HT6150","http://technet.microsoft.com/security/advisory/2588513","http://vnhacker.blogspot.com/2011/09/beast.html","http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf","http://www.debian.org/security/2012/dsa-2398","http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html","http://www.ibm.com/developerworks/java/jdk/alerts/","http://www.imperialviolet.org/2011/09/23/chromeandbeast.html","http://www.insecure.cl/Beast-SSL.rar","http://www.kb.cert.org/vuls/id/864643","http://www.mandriva.com/security/advisories?name=MDVSA-2012:058","http://www.opera.com/docs/changelogs/mac/1151/","http://www.opera.com/docs/changelogs/mac/1160/","http://www.opera.com/docs/changelogs/unix/1151/","http://www.opera.com/docs/changelogs/unix/1160/","http://www.opera.com/docs/changelogs/windows/1151/","http://www.opera.com/docs/changelogs/windows/1160/","http://www.opera.com/support/kb/view/1004/","http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html","http://www.redhat.com/support/errata/RHSA-2011-1384.html","http://www.redhat.com/support/errata/RHSA-2012-0006.html","http://www.securityfocus.com/bid/49388","http://www.securityfocus.com/bid/49778","http://www.securitytracker.com/id/1029190","http://www.securitytracker.com/id?1025997","http://www.securitytracker.com/id?1026103","http://www.securitytracker.com/id?1026704","http://www.ubuntu.com/usn/USN-1263-1","http://www.us-cert.gov/cas/techalerts/TA12-010A.html","https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail","https://bugzilla.novell.com/show_bug.cgi?id=719047","https://bugzilla.redhat.com/show_bug.cgi?id=737506","https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006","https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862","https://hermes.opensuse.org/messages/13154861","https://hermes.opensuse.org/messages/13155432","https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2008-0456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-0456","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-0456","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-0456","date":"2026-10-08","epss":0.19036,"percentile":0.97244}],"risk":0.9518000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-0456","description":"CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."},"relatedVulnerabilities":[{"id":"CVE-2008-0456","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-0456","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-0456","date":"2026-10-08","epss":0.19036,"percentile":0.97244}],"urls":["http://lists.apple.com/archives/security-announce/2009/May/msg00002.html","http://rhn.redhat.com/errata/RHSA-2013-0130.html","http://secunia.com/advisories/29348","http://secunia.com/advisories/35074","http://security.gentoo.org/glsa/glsa-200803-19.xml","http://securityreason.com/securityalert/3575","http://securitytracker.com/id?1019256","http://support.apple.com/kb/HT3549","http://www.mindedsecurity.com/MSA01150108.html","http://www.securityfocus.com/archive/1/486847/100/0/threaded","http://www.securityfocus.com/bid/27409","http://www.us-cert.gov/cas/techalerts/TA09-133A.html","http://www.vupen.com/english/advisories/2009/1297","https://exchange.xforce.ibmcloud.com/vulnerabilities/39893","https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-0456","description":"CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2008-0456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-0456","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-0456","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-0456","date":"2026-10-08","epss":0.19036,"percentile":0.97244}],"risk":0.9518000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-0456","description":"CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."},"relatedVulnerabilities":[{"id":"CVE-2008-0456","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-0456","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-0456","date":"2026-10-08","epss":0.19036,"percentile":0.97244}],"urls":["http://lists.apple.com/archives/security-announce/2009/May/msg00002.html","http://rhn.redhat.com/errata/RHSA-2013-0130.html","http://secunia.com/advisories/29348","http://secunia.com/advisories/35074","http://security.gentoo.org/glsa/glsa-200803-19.xml","http://securityreason.com/securityalert/3575","http://securitytracker.com/id?1019256","http://support.apple.com/kb/HT3549","http://www.mindedsecurity.com/MSA01150108.html","http://www.securityfocus.com/archive/1/486847/100/0/threaded","http://www.securityfocus.com/bid/27409","http://www.us-cert.gov/cas/techalerts/TA09-133A.html","http://www.vupen.com/english/advisories/2009/1297","https://exchange.xforce.ibmcloud.com/vulnerabilities/39893","https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-0456","description":"CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2008-0456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-0456","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-0456","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-0456","date":"2026-10-08","epss":0.19036,"percentile":0.97244}],"risk":0.9518000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-0456","description":"CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."},"relatedVulnerabilities":[{"id":"CVE-2008-0456","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-0456","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-0456","date":"2026-10-08","epss":0.19036,"percentile":0.97244}],"urls":["http://lists.apple.com/archives/security-announce/2009/May/msg00002.html","http://rhn.redhat.com/errata/RHSA-2013-0130.html","http://secunia.com/advisories/29348","http://secunia.com/advisories/35074","http://security.gentoo.org/glsa/glsa-200803-19.xml","http://securityreason.com/securityalert/3575","http://securitytracker.com/id?1019256","http://support.apple.com/kb/HT3549","http://www.mindedsecurity.com/MSA01150108.html","http://www.securityfocus.com/archive/1/486847/100/0/threaded","http://www.securityfocus.com/bid/27409","http://www.us-cert.gov/cas/techalerts/TA09-133A.html","http://www.vupen.com/english/advisories/2009/1297","https://exchange.xforce.ibmcloud.com/vulnerabilities/39893","https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-0456","description":"CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2008-0456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-0456","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-0456","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-0456","date":"2026-10-08","epss":0.19036,"percentile":0.97244}],"risk":0.9518000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-0456","description":"CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."},"relatedVulnerabilities":[{"id":"CVE-2008-0456","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-0456","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-0456","date":"2026-10-08","epss":0.19036,"percentile":0.97244}],"urls":["http://lists.apple.com/archives/security-announce/2009/May/msg00002.html","http://rhn.redhat.com/errata/RHSA-2013-0130.html","http://secunia.com/advisories/29348","http://secunia.com/advisories/35074","http://security.gentoo.org/glsa/glsa-200803-19.xml","http://securityreason.com/securityalert/3575","http://securitytracker.com/id?1019256","http://support.apple.com/kb/HT3549","http://www.mindedsecurity.com/MSA01150108.html","http://www.securityfocus.com/archive/1/486847/100/0/threaded","http://www.securityfocus.com/bid/27409","http://www.us-cert.gov/cas/techalerts/TA09-133A.html","http://www.vupen.com/english/advisories/2009/1297","https://exchange.xforce.ibmcloud.com/vulnerabilities/39893","https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-0456","description":"CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63292","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63292","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"risk":0.657,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63292","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63292","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"risk":0.657,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63292","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63292","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"risk":0.657,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63292","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63292","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"risk":0.657,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66046","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66046","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"risk":0.60102,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."},"relatedVulnerabilities":[{"id":"CVE-2026-66046","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"urls":["https://github.com/libexpat/libexpat/pull/1321","https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57941","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57941","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"risk":0.5640000000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-57941","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/19"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57941","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57941","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"risk":0.5640000000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-57941","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/19"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57941","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57941","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"risk":0.5640000000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-57941","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/19"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57941","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57941","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"risk":0.5640000000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-57941","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/19"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9079","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"risk":0.54896,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them."},"relatedVulnerabilities":[{"id":"CVE-2026-9079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9079","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"risk":0.54896,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them."},"relatedVulnerabilities":[{"id":"CVE-2026-9079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56154","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56154","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"risk":0.5282800000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56154","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56154","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56154","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"risk":0.5282800000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56154","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56154","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56154","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"risk":0.5282800000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56154","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56154","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56154","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"risk":0.5282800000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56154","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6988","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-6988","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"risk":0.5172,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6988","description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress."},"relatedVulnerabilities":[{"id":"CVE-2019-6988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"urls":["http://www.securityfocus.com/bid/106785","https://github.com/uclouvain/openjpeg/issues/1178"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6988","description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2007-0086","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2007-0086","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-0086","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-0086","date":"2026-10-08","epss":0.10168,"percentile":0.95552}],"risk":0.5084000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-0086","description":"The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal"},"relatedVulnerabilities":[{"id":"CVE-2007-0086","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"impactScore":6.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-0086","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-0086","date":"2026-10-08","epss":0.10168,"percentile":0.95552}],"urls":["http://osvdb.org/33456","http://www.securityfocus.com/archive/1/455833/100/0/threaded","http://www.securityfocus.com/archive/1/455879/100/0/threaded","http://www.securityfocus.com/archive/1/455882/100/0/threaded","http://www.securityfocus.com/archive/1/455920/100/0/threaded"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-0086","description":"The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal"}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-0086","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2007-0086","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-0086","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-0086","date":"2026-10-08","epss":0.10168,"percentile":0.95552}],"risk":0.5084000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-0086","description":"The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal"},"relatedVulnerabilities":[{"id":"CVE-2007-0086","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"impactScore":6.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-0086","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-0086","date":"2026-10-08","epss":0.10168,"percentile":0.95552}],"urls":["http://osvdb.org/33456","http://www.securityfocus.com/archive/1/455833/100/0/threaded","http://www.securityfocus.com/archive/1/455879/100/0/threaded","http://www.securityfocus.com/archive/1/455882/100/0/threaded","http://www.securityfocus.com/archive/1/455920/100/0/threaded"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-0086","description":"The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal"}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-0086","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2007-0086","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-0086","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-0086","date":"2026-10-08","epss":0.10168,"percentile":0.95552}],"risk":0.5084000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-0086","description":"The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal"},"relatedVulnerabilities":[{"id":"CVE-2007-0086","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"impactScore":6.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-0086","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-0086","date":"2026-10-08","epss":0.10168,"percentile":0.95552}],"urls":["http://osvdb.org/33456","http://www.securityfocus.com/archive/1/455833/100/0/threaded","http://www.securityfocus.com/archive/1/455879/100/0/threaded","http://www.securityfocus.com/archive/1/455882/100/0/threaded","http://www.securityfocus.com/archive/1/455920/100/0/threaded"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-0086","description":"The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal"}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-0086","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2007-0086","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-0086","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-0086","date":"2026-10-08","epss":0.10168,"percentile":0.95552}],"risk":0.5084000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-0086","description":"The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal"},"relatedVulnerabilities":[{"id":"CVE-2007-0086","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"impactScore":6.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-0086","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-0086","date":"2026-10-08","epss":0.10168,"percentile":0.95552}],"urls":["http://osvdb.org/33456","http://www.securityfocus.com/archive/1/455833/100/0/threaded","http://www.securityfocus.com/archive/1/455879/100/0/threaded","http://www.securityfocus.com/archive/1/455882/100/0/threaded","http://www.securityfocus.com/archive/1/455920/100/0/threaded"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-0086","description":"The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal"}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59797","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59797","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"risk":0.4888,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-59797","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/22"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59797","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59797","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"risk":0.4888,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-59797","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/22"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59797","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59797","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"risk":0.4888,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-59797","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/22"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59797","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59797","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"risk":0.4888,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-59797","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/22"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"e2c0cfe2f366c89d","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u3:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u3?arch=amd64&distro=debian-13.7&upstream=tiff","type":"deb","version":"4.7.0-3+deb13u3","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-52490","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tiff","version":"4.7.0-3+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-52490","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-52490","date":"2026-10-08","epss":0.0051,"percentile":0.41671}],"risk":0.47940000000000005,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-52490","description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c"},"relatedVulnerabilities":[{"id":"CVE-2026-52490","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-52490","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-52490","date":"2026-10-08","epss":0.0051,"percentile":0.41671}],"urls":["https://gist.github.com/okyfh/122c2d72e991a78c8af80a3af3be8671","https://gitlab.com/libtiff/libtiff/-/work_items/846"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-52490","description":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c"}]},{"artifact":{"id":"e9d28bf4fecb65b4","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"8d18bdf2d28de8c0","cpes":["cpe:2.3:a:perl:perl:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"1ed310f43f3fc66d","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"ec18de78d97e6b78","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6%2Bdeb13u1?arch=all&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56449","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56449","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"risk":0.45899999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56449","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/18"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56449","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56449","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"risk":0.45899999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56449","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/18"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56449","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56449","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"risk":0.45899999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56449","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/18"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56449","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56449","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"risk":0.45899999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56449","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/18"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-48005","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48005","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"risk":0.4545,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-48005","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/15"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48005","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48005","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"risk":0.4545,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-48005","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/15"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48005","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48005","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"risk":0.4545,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-48005","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/15"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48005","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48005","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"risk":0.4545,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-48005","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/15"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.430965,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80229","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"risk":0.42224999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations."},"relatedVulnerabilities":[{"id":"CVE-2026-80229","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80229","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"risk":0.42224999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations."},"relatedVulnerabilities":[{"id":"CVE-2026-80229","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."}]},{"artifact":{"id":"ca88752821693d8d","cpes":["cpe:2.3:a:patch:patch:2.8-2:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.8-2?arch=amd64&distro=debian-13.7","type":"deb","version":"2.8-2","language":"","licenses":["GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6951","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"patch","version":"2.8-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-6951","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6951","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6951","date":"2026-10-08","epss":0.08359,"percentile":0.94832}],"risk":0.41795,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6951","description":"An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a \"mangled rename\" issue."},"relatedVulnerabilities":[{"id":"CVE-2018-6951","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6951","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6951","date":"2026-10-08","epss":0.08359,"percentile":0.94832}],"urls":["http://www.securityfocus.com/bid/103044","https://git.savannah.gnu.org/cgit/patch.git/commit/?id=f290f48a621867084884bfff87f8093c15195e6a","https://savannah.gnu.org/bugs/index.php?53132","https://security.gentoo.org/glsa/201904-17","https://usn.ubuntu.com/3624-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6951","description":"An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a \"mangled rename\" issue."}]},{"artifact":{"id":"ca88752821693d8d","cpes":["cpe:2.3:a:patch:patch:2.8-2:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.8-2?arch=amd64&distro=debian-13.7","type":"deb","version":"2.8-2","language":"","licenses":["GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6952","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"patch","version":"2.8-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-6952","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6952","date":"2026-10-08","epss":0.0819,"percentile":0.94738}],"risk":0.40950000000000003,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6952","description":"A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6."},"relatedVulnerabilities":[{"id":"CVE-2018-6952","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6952","date":"2026-10-08","epss":0.0819,"percentile":0.94738}],"urls":["http://www.securityfocus.com/bid/103047","https://access.redhat.com/errata/RHSA-2019:2033","https://savannah.gnu.org/bugs/index.php?53133","https://security.gentoo.org/glsa/201904-17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6952","description":"A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8926","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8926","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"risk":0.40182000000000007,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user."},"relatedVulnerabilities":[{"id":"CVE-2026-8926","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8926","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8926","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"risk":0.40182000000000007,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user."},"relatedVulnerabilities":[{"id":"CVE-2026-8926","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-34152","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-34152","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"risk":0.40055,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."},"relatedVulnerabilities":[{"id":"CVE-2023-34152","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-34152","cwe":"CWE-20","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-34152","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-34152","date":"2026-10-08","epss":0.08011,"percentile":0.94633}],"urls":["https://access.redhat.com/security/cve/CVE-2023-34152","https://bugzilla.redhat.com/show_bug.cgi?id=2210659","https://github.com/ImageMagick/ImageMagick/issues/6339","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UFQJCYJ23HWHNDOVKBHZQ7HCXXL6MM3/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2ZUHZXQ2C3JZYKPW4XHCMVVL467MA2V/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-34152","description":"A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63718","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63718","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"risk":0.37424999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.    This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-63718","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/26"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63718","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63718","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"risk":0.37424999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.    This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-63718","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/26"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63718","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63718","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"risk":0.37424999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.    This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-63718","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/26"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63718","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63718","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"risk":0.37424999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.    This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-63718","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/26"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56153","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56153","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"risk":0.3735,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56153","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56153","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56153","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"risk":0.3735,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56153","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56153","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56153","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"risk":0.3735,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56153","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56153","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56153","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"risk":0.3735,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56153","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"risk":0.36556,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed."},"relatedVulnerabilities":[{"id":"CVE-2026-9080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"risk":0.36556,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed."},"relatedVulnerabilities":[{"id":"CVE-2026-9080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80255","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host."},"relatedVulnerabilities":[{"id":"CVE-2026-80255","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80255","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host."},"relatedVulnerabilities":[{"id":"CVE-2026-80255","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63686","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63686","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63686","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/25"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63686","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63686","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63686","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/25"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63686","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63686","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63686","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/25"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63686","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63686","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63686","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/25"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-73637","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73637","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"risk":0.35816,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-73637","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/28"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73637","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73637","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"risk":0.35816,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-73637","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/28"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73637","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73637","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"risk":0.35816,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-73637","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/28"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73637","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73637","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"risk":0.35816,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-73637","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/28"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-93546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93546","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"risk":0.35534000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."},"relatedVulnerabilities":[{"id":"CVE-2026-93546","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/30"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93546","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"risk":0.35534000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."},"relatedVulnerabilities":[{"id":"CVE-2026-93546","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/30"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93546","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"risk":0.35534000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."},"relatedVulnerabilities":[{"id":"CVE-2026-93546","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/30"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93546","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"risk":0.35534000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."},"relatedVulnerabilities":[{"id":"CVE-2026-93546","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/30"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63045","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63045","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"risk":0.35400000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63045","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63045","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63045","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"risk":0.35400000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63045","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63045","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63045","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"risk":0.35400000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63045","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63045","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63045","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"risk":0.35400000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63045","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"614dd2dfa62b9595","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.7&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap2/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libldap2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-17740","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2017-17740","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-08","epss":0.07022,"percentile":0.94018}],"risk":0.3511,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."},"relatedVulnerabilities":[{"id":"CVE-2017-17740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-08","epss":0.07022,"percentile":0.94018}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://www.openldap.org/its/index.cgi/Incoming?id=8759","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-46729","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-46729","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"risk":0.35100000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-46729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46729","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-46729","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"risk":0.35100000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-46729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46729","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-46729","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"risk":0.35100000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-46729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46729","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-46729","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"risk":0.35100000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-46729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-74860","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-74860","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"risk":0.3488,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."},"relatedVulnerabilities":[{"id":"CVE-2026-74860","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"urls":["https://access.redhat.com/errata/RHSA-2026:64463","https://access.redhat.com/errata/RHSA-2026:71585","https://access.redhat.com/errata/RHSA-2026:71586","https://access.redhat.com/errata/RHSA-2026:71641","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/security/cve/CVE-2026-74860","https://bugzilla.redhat.com/show_bug.cgi?id=2529697"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."}]},{"artifact":{"id":"50f3e6307c72b0b7","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.34299,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"e0cedc6dccd6380c","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.34299,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"f8b8769b671bcd56","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.34299,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"212a71fa16031fdf","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"7402a3d31bb024db","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"3f9378db54aaac9e","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"e96cb50e09a471e0","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.33975000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39329","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-39329","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"risk":0.33809999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39329","description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2023-39329","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39329","https://bugzilla.redhat.com/show_bug.cgi?id=2295816","https://github.com/uclouvain/openjpeg/issues/1474"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39329","description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service."}]},{"artifact":{"id":"e9d28bf4fecb65b4","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"8d18bdf2d28de8c0","cpes":["cpe:2.3:a:perl:perl:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"1ed310f43f3fc66d","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"ec18de78d97e6b78","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6%2Bdeb13u1?arch=all&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6653","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6653","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-6653","cwe":"CWE-611","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-6653","date":"2026-10-08","epss":0.00355,"percentile":0.27192}],"risk":0.33370000000000005,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6653","description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling."},"relatedVulnerabilities":[{"id":"CVE-2026-6653","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@ubuntu.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6653","cwe":"CWE-416","type":"Secondary","source":"security@ubuntu.com"},{"cve":"CVE-2026-6653","cwe":"CWE-611","type":"Secondary","source":"security@ubuntu.com"}],"epss":[{"cve":"CVE-2026-6653","date":"2026-10-08","epss":0.00355,"percentile":0.27192}],"urls":["https://bugs.launchpad.net/ubuntu/+source/libxml2/+bug/2141260","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6653","description":"Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.32642999999999994,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-73636","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73636","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"risk":0.32136000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-73636","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73636","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73636","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"risk":0.32136000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-73636","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73636","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73636","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"risk":0.32136000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-73636","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73636","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73636","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"risk":0.32136000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-73636","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"f5152615a12aeb3d","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"5c8cb5d5c2e5df78","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"bd4b70ba8c48d583","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"cfe9c78846143096","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"a6e51e84db754048","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"faedc3139e685610","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"9db9d188fa9e89fc","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:4.16.0-2+really2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"bd55752b0f187487","cpes":["cpe:2.3:a:mount:mount:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"166978fa81223e72","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-08","epss":0.00621,"percentile":0.48148}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"risk":0.30600000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.  When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-9545","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"risk":0.30600000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.  When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-9545","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-79768","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-79768","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"risk":0.30385,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-79768","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/29"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-79768","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-79768","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"risk":0.30385,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-79768","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/29"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-79768","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-79768","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"risk":0.30385,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-79768","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/29"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-79768","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-79768","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"risk":0.30385,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-79768","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/29"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"1f32975dfd37be95","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/debian/libpam-modules@1.7.0-5?arch=amd64&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"cb7fdbb7b6a04bdc","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/debian/libpam-modules-bin@1.7.0-5?arch=amd64&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"eb5873c5c35e21b8","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/debian/libpam-runtime@1.7.0-5?arch=all&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"1c6c7728b37b94de","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/debian/libpam0g@1.7.0-5?arch=amd64&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-47360","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-47360","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"risk":0.2895,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.        When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.      This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-47360","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/14"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.\n\n\n\n   \nWhen SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.\n\n\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47360","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-47360","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"risk":0.2895,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.        When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.      This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-47360","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/14"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.\n\n\n\n   \nWhen SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.\n\n\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47360","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-47360","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"risk":0.2895,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.        When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.      This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-47360","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/14"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.\n\n\n\n   \nWhen SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.\n\n\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47360","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-47360","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"risk":0.2895,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.        When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.      This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-47360","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/14"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.\n\n\n\n   \nWhen SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.\n\n\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"50f3e6307c72b0b7","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52615","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"risk":0.28891500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."},"relatedVulnerabilities":[{"id":"CVE-2024-52615","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."}]},{"artifact":{"id":"e0cedc6dccd6380c","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52615","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"risk":0.28891500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."},"relatedVulnerabilities":[{"id":"CVE-2024-52615","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."}]},{"artifact":{"id":"f8b8769b671bcd56","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-52615","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"risk":0.28891500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."},"relatedVulnerabilities":[{"id":"CVE-2024-52615","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-08","epss":0.05757,"percentile":0.9288}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"8a1ec6d9372df578","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.7&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"e2c0cfe2f366c89d","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u3:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u3?arch=amd64&distro=debian-13.7&upstream=tiff","type":"deb","version":"4.7.0-3+deb13u3","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-16232","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tiff","version":"4.7.0-3+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2017-16232","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16232","date":"2026-10-08","epss":0.05584,"percentile":0.92685}],"risk":0.2792,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-16232","description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue"},"relatedVulnerabilities":[{"id":"CVE-2017-16232","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-16232","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-16232","date":"2026-10-08","epss":0.05584,"percentile":0.92685}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00036.html","http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00041.html","http://packetstormsecurity.com/files/150896/LibTIFF-4.0.8-Memory-Leak.html","http://seclists.org/fulldisclosure/2018/Dec/32","http://seclists.org/fulldisclosure/2018/Dec/47","http://www.openwall.com/lists/oss-security/2017/11/01/11","http://www.openwall.com/lists/oss-security/2017/11/01/3","http://www.openwall.com/lists/oss-security/2017/11/01/7","http://www.openwall.com/lists/oss-security/2017/11/01/8","http://www.securityfocus.com/bid/101696"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-16232","description":"LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue"}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"f192cb8dc63f3eb4","cpes":["cpe:2.3:a:cpp-14:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"cpp-14","purl":"pkg:deb/debian/cpp-14@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/cpp-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/cpp-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/cpp-14.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"1580254f2d5cda2a","cpes":["cpe:2.3:a:cpp-14-x86-64-linux-gnu:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux-gnu:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux_gnu:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux_gnu:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"cpp-14-x86-64-linux-gnu","purl":"pkg:deb/debian/cpp-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/cpp-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"bf427850ceb9b9cf","cpes":["cpe:2.3:a:g\\+\\+-14:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"g++-14","purl":"pkg:deb/debian/g%2B%2B-14@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/g++-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/g++-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/g++-14.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"64cb91ba3690d600","cpes":["cpe:2.3:a:g\\+\\+-14-x86-64-linux-gnu:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux-gnu:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux_gnu:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux_gnu:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"g++-14-x86-64-linux-gnu","purl":"pkg:deb/debian/g%2B%2B-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/g++-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"1753e0ab4835d319","cpes":["cpe:2.3:a:gcc-14:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14","purl":"pkg:deb/debian/gcc-14@14.2.0-19?arch=amd64&distro=debian-13.7","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/gcc-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/gcc-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/gcc-14.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"8a928cc6733b8d4c","cpes":["cpe:2.3:a:gcc-14-base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-base","purl":"pkg:deb/debian/gcc-14-base@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/gcc-14-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"afc74f4635aa2de5","cpes":["cpe:2.3:a:gcc-14-x86-64-linux-gnu:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux-gnu:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux_gnu:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux_gnu:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-x86-64-linux-gnu","purl":"pkg:deb/debian/gcc-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/gcc-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"7475a27907fe4420","cpes":["cpe:2.3:a:libasan8:libasan8:14.2.0-19:*:*:*:*:*:*:*"],"name":"libasan8","purl":"pkg:deb/debian/libasan8@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libasan8/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasan8:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libasan8:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"4aef59838e786012","cpes":["cpe:2.3:a:libatomic1:libatomic1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libatomic1","purl":"pkg:deb/debian/libatomic1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libatomic1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"062249237978e3de","cpes":["cpe:2.3:a:libcc1-0:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1-0:libcc1_0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1_0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1_0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libcc1-0","purl":"pkg:deb/debian/libcc1-0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libcc1-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"ef5dd5e55126a732","cpes":["cpe:2.3:a:libgcc-14-dev:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14-dev:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14_dev:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14_dev:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-14-dev","purl":"pkg:deb/debian/libgcc-14-dev@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libgcc-14-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-14-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libgcc-14-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"2338ed612a82adf3","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"71d32d5417d636ce","cpes":["cpe:2.3:a:libgomp1:libgomp1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgomp1","purl":"pkg:deb/debian/libgomp1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libgomp1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"81d0f863177c4ff2","cpes":["cpe:2.3:a:libhwasan0:libhwasan0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libhwasan0","purl":"pkg:deb/debian/libhwasan0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libhwasan0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhwasan0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libhwasan0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"30ada6cb82fd6f02","cpes":["cpe:2.3:a:libitm1:libitm1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libitm1","purl":"pkg:deb/debian/libitm1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libitm1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libitm1:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libitm1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"d3f0e91aac2169e5","cpes":["cpe:2.3:a:liblsan0:liblsan0:14.2.0-19:*:*:*:*:*:*:*"],"name":"liblsan0","purl":"pkg:deb/debian/liblsan0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/liblsan0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"2e7766dcd5ecb5f3","cpes":["cpe:2.3:a:libquadmath0:libquadmath0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libquadmath0","purl":"pkg:deb/debian/libquadmath0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libquadmath0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"0f0a43dbd793abf5","cpes":["cpe:2.3:a:libstdc\\+\\+-14-dev:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14-dev:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14_dev:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14_dev:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++-14-dev","purl":"pkg:deb/debian/libstdc%2B%2B-14-dev@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libstdc++-14-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++-14-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libstdc++-14-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"7dc961cf921ecd08","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"3faa4e2eb1e6610c","cpes":["cpe:2.3:a:libtsan2:libtsan2:14.2.0-19:*:*:*:*:*:*:*"],"name":"libtsan2","purl":"pkg:deb/debian/libtsan2@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libtsan2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"79fd96516c7017fa","cpes":["cpe:2.3:a:libubsan1:libubsan1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libubsan1","purl":"pkg:deb/debian/libubsan1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libubsan1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58415","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58415","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"risk":0.274495,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-58415","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/20"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58415","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58415","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"risk":0.274495,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-58415","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/20"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58415","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58415","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"risk":0.274495,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-58415","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/20"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58415","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58415","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"risk":0.274495,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-58415","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/20"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-61915","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-61915","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61915","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-61915","cwe":"CWE-129","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-61915","date":"2026-10-08","epss":0.00462,"percentile":0.3811}],"risk":0.27026999999999995,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-61915","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15."},"relatedVulnerabilities":[{"id":"CVE-2025-61915","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H","metrics":{"baseScore":6,"impactScore":4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61915","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-61915","cwe":"CWE-129","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-61915","date":"2026-10-08","epss":0.00462,"percentile":0.3811}],"urls":["https://github.com/OpenPrinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","https://github.com/OpenPrinting/cups/releases/tag/v2.4.15","https://github.com/OpenPrinting/cups/security/advisories/GHSA-hxm8-vfpq-jrfc","http://www.openwall.com/lists/oss-security/2025/11/27/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61915","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15."}]},{"artifact":{"id":"614dd2dfa62b9595","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.7&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap2/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libldap2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-3276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2015-3276","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-08","epss":0.05269,"percentile":0.92348}],"risk":0.26345,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."},"relatedVulnerabilities":[{"id":"CVE-2015-3276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-08","epss":0.05269,"percentile":0.92348}],"urls":["http://rhn.redhat.com/errata/RHSA-2015-2131.html","http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","http://www.securitytracker.com/id/1034221","https://bugzilla.redhat.com/show_bug.cgi?id=1238322"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15607","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-15607","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"risk":0.26065000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."},"relatedVulnerabilities":[{"id":"CVE-2018-15607","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15607","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-15607","date":"2026-10-08","epss":0.05213,"percentile":0.9229}],"urls":["http://www.securityfocus.com/bid/105137","https://github.com/ImageMagick/ImageMagick/issues/1255","https://usn.ubuntu.com/4034-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15607","description":"In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39327","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-39327","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39327","date":"2026-10-08","epss":0.00555,"percentile":0.44547}],"risk":0.258075,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39327","description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal."},"relatedVulnerabilities":[{"id":"CVE-2023-39327","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39327","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39327","date":"2026-10-08","epss":0.00555,"percentile":0.44547}],"urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39327","https://bugzilla.redhat.com/show_bug.cgi?id=2295812","https://github.com/uclouvain/openjpeg/issues/1472"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39327","description":"A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal."}]},{"artifact":{"id":"69f2cf32e9bda724","cpes":["cpe:2.3:a:libde265-0:libde265-0:1.0.15-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265-0:libde265_0:1.0.15-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265-0:1.0.15-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265_0:libde265_0:1.0.15-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265-0:1.0.15-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libde265:libde265_0:1.0.15-1\\+deb13u2:*:*:*:*:*:*:*"],"name":"libde265-0","purl":"pkg:deb/debian/libde265-0@1.0.15-1%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=libde265","type":"deb","version":"1.0.15-1+deb13u2","language":"","licenses":["BSD-4-clause","GPL-3","GPL-3+","LGPL-3","LGPL-3+","other-1","public-domain-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libde265-0/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libde265-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libde265-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libde265"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-88373","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libde265","version":"1.0.15-1+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-88373","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88373","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-88373","date":"2026-10-08","epss":0.00343,"percentile":0.25785}],"risk":0.25725000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-88373","description":"libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting NAL_unit may retain a NULL backing buffer, which is subsequently passed as the destination argument to memcpy() in NAL_unit::set_data(). Although the copy length is zero, this violates the nonnull requirement of memcpy() and results in undefined behavior, causing process termination in UBSan-instrumented builds and denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-88373","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88373","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-88373","date":"2026-10-08","epss":0.00343,"percentile":0.25785}],"urls":["https://github.com/strukturag/libde265/commit/f8d324914e43d92af23614f22959cf9eee7bf9ea","https://github.com/strukturag/libde265/issues/534"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88373","description":"libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting NAL_unit may retain a NULL backing buffer, which is subsequently passed as the destination argument to memcpy() in NAL_unit::set_data(). Although the copy length is zero, this violates the nonnull requirement of memcpy() and results in undefined behavior, causing process termination in UBSan-instrumented builds and denial of service."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34980","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34980","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34980","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34980","date":"2026-10-08","epss":0.00335,"percentile":0.24876}],"risk":0.25125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34980","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches."},"relatedVulnerabilities":[{"id":"CVE-2026-34980","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34980","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34980","date":"2026-10-08","epss":0.00335,"percentile":0.24876}],"urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-4852-v58g-6cwf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34980","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches."}]},{"artifact":{"id":"87a086ab1a842620","cpes":["cpe:2.3:a:ghostscript:ghostscript:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*"],"name":"ghostscript","purl":"pkg:deb/debian/ghostscript@10.05.1~dfsg-1%2Bdeb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"10.05.1~dfsg-1+deb13u2","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ghostscript/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/ghostscript/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ghostscript.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/ghostscript.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ghostscript.list","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/ghostscript.list"},{"path":"/var/lib/dpkg/info/ghostscript.postinst","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/ghostscript.postinst"},{"path":"/var/lib/dpkg/info/ghostscript.prerm","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/ghostscript.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103226","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ghostscript","version":"10.05.1~dfsg-1+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103226","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"risk":0.2486,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""},"relatedVulnerabilities":[{"id":"CVE-2026-103226","cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"urls":["https://artifex.com/","https://bugs.ghostscript.com/attachment.cgi?id=28495","https://bugs.ghostscript.com/show_bug.cgi?id=709672","https://bugs.ghostscript.com/show_bug.cgi?id=709672#c3","https://vuldb.com/cve/CVE-2026-103226","https://vuldb.com/submit/955016","https://vuldb.com/vuln/411906","https://vuldb.com/vuln/411906/cti"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""}]},{"artifact":{"id":"3c7a92703086b14e","cpes":["cpe:2.3:a:libgs-common:libgs-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs-common:libgs_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*"],"name":"libgs-common","purl":"pkg:deb/debian/libgs-common@10.05.1~dfsg-1%2Bdeb13u2?arch=all&distro=debian-13.7&upstream=ghostscript","type":"deb","version":"10.05.1~dfsg-1+deb13u2","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs-common/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libgs-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libgs-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.list","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libgs-common.list"}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103226","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ghostscript","version":"10.05.1~dfsg-1+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103226","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"risk":0.2486,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""},"relatedVulnerabilities":[{"id":"CVE-2026-103226","cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"urls":["https://artifex.com/","https://bugs.ghostscript.com/attachment.cgi?id=28495","https://bugs.ghostscript.com/show_bug.cgi?id=709672","https://bugs.ghostscript.com/show_bug.cgi?id=709672#c3","https://vuldb.com/cve/CVE-2026-103226","https://vuldb.com/submit/955016","https://vuldb.com/vuln/411906","https://vuldb.com/vuln/411906/cti"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""}]},{"artifact":{"id":"750235da747ba01e","cpes":["cpe:2.3:a:libgs10:libgs10:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*"],"name":"libgs10","purl":"pkg:deb/debian/libgs10@10.05.1~dfsg-1%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=ghostscript","type":"deb","version":"10.05.1~dfsg-1+deb13u2","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libgs10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libgs10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103226","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ghostscript","version":"10.05.1~dfsg-1+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103226","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"risk":0.2486,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""},"relatedVulnerabilities":[{"id":"CVE-2026-103226","cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"urls":["https://artifex.com/","https://bugs.ghostscript.com/attachment.cgi?id=28495","https://bugs.ghostscript.com/show_bug.cgi?id=709672","https://bugs.ghostscript.com/show_bug.cgi?id=709672#c3","https://vuldb.com/cve/CVE-2026-103226","https://vuldb.com/submit/955016","https://vuldb.com/vuln/411906","https://vuldb.com/vuln/411906/cti"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""}]},{"artifact":{"id":"33e5c936ca2d2a4a","cpes":["cpe:2.3:a:libgs10-common:libgs10-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs10-common:libgs10_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*"],"name":"libgs10-common","purl":"pkg:deb/debian/libgs10-common@10.05.1~dfsg-1%2Bdeb13u2?arch=all&distro=debian-13.7&upstream=ghostscript","type":"deb","version":"10.05.1~dfsg-1+deb13u2","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10-common/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libgs10-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libgs10-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.list","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libgs10-common.list"}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103226","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ghostscript","version":"10.05.1~dfsg-1+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103226","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"risk":0.2486,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""},"relatedVulnerabilities":[{"id":"CVE-2026-103226","cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"urls":["https://artifex.com/","https://bugs.ghostscript.com/attachment.cgi?id=28495","https://bugs.ghostscript.com/show_bug.cgi?id=709672","https://bugs.ghostscript.com/show_bug.cgi?id=709672#c3","https://vuldb.com/cve/CVE-2026-103226","https://vuldb.com/submit/955016","https://vuldb.com/vuln/411906","https://vuldb.com/vuln/411906/cti"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""}]},{"artifact":{"id":"ca88752821693d8d","cpes":["cpe:2.3:a:patch:patch:2.8-2:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.8-2?arch=amd64&distro=debian-13.7","type":"deb","version":"2.8-2","language":"","licenses":["GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2010-4651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"patch","version":"2.8-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4651","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4651","date":"2026-10-08","epss":0.04874,"percentile":0.91829}],"risk":0.2437,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4651","description":"Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679."},"relatedVulnerabilities":[{"id":"CVE-2010-4651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4651","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4651","date":"2026-10-08","epss":0.04874,"percentile":0.91829}],"urls":["http://git.savannah.gnu.org/cgit/patch.git/commit/?id=685a78b6052f4df6eac6d625a545cfb54a6ac0e1","http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055241.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055246.html","http://lists.gnu.org/archive/html/bug-patch/2010-12/msg00000.html","http://openwall.com/lists/oss-security/2011/01/05/10","http://openwall.com/lists/oss-security/2011/01/06/19","http://openwall.com/lists/oss-security/2011/01/06/20","http://openwall.com/lists/oss-security/2011/01/06/21","http://secunia.com/advisories/43663","http://secunia.com/advisories/43677","http://support.apple.com/kb/HT4723","http://www.securityfocus.com/bid/46768","http://www.vupen.com/english/advisories/2011/0600","https://bugzilla.redhat.com/show_bug.cgi?id=667529"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4651","description":"Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34978","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34978","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34978","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34978","date":"2026-10-08","epss":0.0042,"percentile":0.34261}],"risk":0.24149999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34978","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches."},"relatedVulnerabilities":[{"id":"CVE-2026-34978","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34978","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34978","date":"2026-10-08","epss":0.0042,"percentile":0.34261}],"urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-f53q-7mxp-9gcr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34978","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86420","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86420","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"risk":0.24075,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-86420","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86420","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86420","date":"2026-10-08","epss":0.00321,"percentile":0.23098}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-denial-of-service-memory-budget"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86420","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service."}]},{"artifact":{"id":"50f3e6307c72b0b7","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68471","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"risk":0.23287499999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."},"relatedVulnerabilities":[{"id":"CVE-2025-68471","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."}]},{"artifact":{"id":"e0cedc6dccd6380c","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68471","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"risk":0.23287499999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."},"relatedVulnerabilities":[{"id":"CVE-2025-68471","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."}]},{"artifact":{"id":"f8b8769b671bcd56","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68471","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68471","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"risk":0.23287499999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."},"relatedVulnerabilities":[{"id":"CVE-2025-68471","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68471","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68471","date":"2026-10-08","epss":0.00405,"percentile":0.32682}],"urls":["https://github.com/avahi/avahi/commit/9c6eb53bf2e290aed84b1f207e3ce35c54cc0aa1","https://github.com/avahi/avahi/issues/678","https://github.com/avahi/avahi/security/advisories/GHSA-56rf-42xr-qmmg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68471","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106578","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106578","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106578","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106578","cwe":"CWE-590","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106578","date":"2026-10-08","epss":0.00402,"percentile":0.32322}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/5d29c094020612dc8fb471b10fc1d1cc6e9e4378","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6xf5-c3jx-rp39","https://github.com/ImageMagick/ImageMagick6/commit/bfe0117fd9742b3970383e000978d64e5e04372d","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106578","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a crafted image can cause an invalid memory free in the MVG decoder and crash the process. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106565","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106565","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106565","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106565","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106565","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106565","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e9872c4a165d869e75d10799c47195725ebf4132","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m9c7-gf3j-hx6h","https://github.com/ImageMagick/ImageMagick6/commit/82f752927a552cbba1213b1d023b85e76845774c","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106565","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a missing end-of-file check while reading bzip2-compressed image data can cause an infinite loop and exhaust processing resources. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106567","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106567","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"risk":0.21909000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106567","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106567","cwe":"CWE-196","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106567","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106567","date":"2026-10-08","epss":0.00402,"percentile":0.32321}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f053f778409932d55b95758c4b1516b63191d1eb","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j","https://github.com/ImageMagick/ImageMagick6/commit/61024a2677a3c7973a2dd27170877d8e51419473","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106567","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted PSD file can trigger an integer-conversion error in the PSD decoder on 32-bit builds, causing an infinite loop and denial of service. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"50f3e6307c72b0b7","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68468","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"risk":0.2185,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."},"relatedVulnerabilities":[{"id":"CVE-2025-68468","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."}]},{"artifact":{"id":"e0cedc6dccd6380c","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68468","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"risk":0.2185,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."},"relatedVulnerabilities":[{"id":"CVE-2025-68468","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."}]},{"artifact":{"id":"f8b8769b671bcd56","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68468","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-68468","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"risk":0.2185,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."},"relatedVulnerabilities":[{"id":"CVE-2025-68468","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68468","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68468","date":"2026-10-08","epss":0.0038,"percentile":0.29896}],"urls":["https://github.com/avahi/avahi/commit/f66be13d7f31a3ef806d226bf8b67240179d309a","https://github.com/avahi/avahi/issues/683","https://github.com/avahi/avahi/security/advisories/GHSA-cp79-r4x9-vf52"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68468","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they expire avahi-daemon crashes."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76956","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76956","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76956","cwe":"CWE-394","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76956","date":"2026-10-08","epss":0.00287,"percentile":0.19503}],"risk":0.21525,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76956","description":"In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content."},"relatedVulnerabilities":[{"id":"CVE-2026-76956","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76956","cwe":"CWE-394","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76956","date":"2026-10-08","epss":0.00287,"percentile":0.19503}],"urls":["https://github.com/libexpat/libexpat/pull/1326","https://github.com/libexpat/libexpat/pull/1329"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76956","description":"In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34979","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34979","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34979","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34979","date":"2026-10-08","epss":0.00413,"percentile":0.33531}],"risk":0.212695,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34979","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer overflow in the CUPS scheduler when building filter option strings from job attribute. At time of publication, there are no publicly available patches."},"relatedVulnerabilities":[{"id":"CVE-2026-34979","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34979","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34979","date":"2026-10-08","epss":0.00413,"percentile":0.33531}],"urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-6qxf-7jx6-86fh"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34979","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer overflow in the CUPS scheduler when building filter option strings from job attribute. At time of publication, there are no publicly available patches."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-41079","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41079","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41079","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41079","date":"2026-10-08","epss":0.00409,"percentile":0.33022}],"risk":0.21267999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41079","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17."},"relatedVulnerabilities":[{"id":"CVE-2026-41079","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41079","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41079","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41079","date":"2026-10-08","epss":0.00409,"percentile":0.33022}],"urls":["https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080","https://github.com/OpenPrinting/cups/commit/d7fe0f521ff3b24676511e747b058362b9a20737","https://github.com/OpenPrinting/cups/security/advisories/GHSA-6wpw-g8g6-wvrv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41079","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17."}]},{"artifact":{"id":"213d133cc46bf69b","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.7","type":"deb","version":"1.35+dfsg-3.1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5704","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5704","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"risk":0.210525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."},"relatedVulnerabilities":[{"id":"CVE-2026-5704","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"urls":["https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66514","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-5704","https://bugzilla.redhat.com/show_bug.cgi?id=2455360","http://www.openwall.com/lists/oss-security/2026/04/11/10","http://www.openwall.com/lists/oss-security/2026/04/11/11","http://www.openwall.com/lists/oss-security/2026/04/12/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."}]},{"artifact":{"id":"213d133cc46bf69b","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.7","type":"deb","version":"1.35+dfsg-3.1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2005-2541","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2005-2541","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"risk":0.1996,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."},"relatedVulnerabilities":[{"id":"CVE-2005-2541","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"urls":["http://marc.info/?l=bugtraq&m=112327628230258&w=2","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106568","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106568","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106568","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106568","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106568","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted XMP profile embedded in an image can cause the profile parser to enter an infinite loop, preventing image processing from completing. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106568","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106568","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106568","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e4f7ad983df6c831832eba3689f96b75f8b67051","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9p7q-63hw-mcr4","https://github.com/ImageMagick/ImageMagick6/commit/27e36ca5cb446664bfc284d28d91fced8887b025","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106568","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted XMP profile embedded in an image can cause the profile parser to enter an infinite loop, preventing image processing from completing. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106569","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106569","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106569","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106569","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106569","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106569","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder allow a crafted ASE image to cause a crash or a long-running operation. This issue is fixed in version 7.1.2-32."},"relatedVulnerabilities":[{"id":"CVE-2026-106569","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106569","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106569","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106569","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/0691546106f4c7e8857da9f21a0e4a8f41915388","https://github.com/ImageMagick/ImageMagick/commit/5ecd5b047cee7ccfe4e14a733a0755c7b2a90c7d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gwj6-pm7x-3r63"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106569","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder allow a crafted ASE image to cause a crash or a long-running operation. This issue is fixed in version 7.1.2-32."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106572","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106572","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106572","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106572","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106572","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a missing recursion-depth check in the CALS decoder allows a crafted CALS image to exhaust the call stack and terminate the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-106572","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106572","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106572","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/19bce64e3667ff03","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wxw6-98rj-hjfr","https://github.com/ImageMagick/ImageMagick6/commit/0ca580238abba18910cfee0fcc3159621fec0dee","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106572","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a missing recursion-depth check in the CALS decoder allows a crafted CALS image to exhaust the call stack and terminate the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106573","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106573","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106573","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106573","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106573","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing limit check in the MVG decoder allows a crafted MVG image to trigger an excessively long-running operation. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106573","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106573","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106573","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/c311471c4e4978494834c707b417bc033d95cc48","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qr53-hc3p-fc62","https://github.com/ImageMagick/ImageMagick6/commit/49560a1641f72a127e413b9861eca0997fde2b96","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106573","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing limit check in the MVG decoder allows a crafted MVG image to trigger an excessively long-running operation. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106568","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106568","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106568","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106568","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106568","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted XMP profile embedded in an image can cause the profile parser to enter an infinite loop, preventing image processing from completing. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106568","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106568","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106568","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e4f7ad983df6c831832eba3689f96b75f8b67051","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9p7q-63hw-mcr4","https://github.com/ImageMagick/ImageMagick6/commit/27e36ca5cb446664bfc284d28d91fced8887b025","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106568","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted XMP profile embedded in an image can cause the profile parser to enter an infinite loop, preventing image processing from completing. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106569","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106569","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106569","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106569","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106569","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106569","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder allow a crafted ASE image to cause a crash or a long-running operation. This issue is fixed in version 7.1.2-32."},"relatedVulnerabilities":[{"id":"CVE-2026-106569","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106569","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106569","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106569","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/0691546106f4c7e8857da9f21a0e4a8f41915388","https://github.com/ImageMagick/ImageMagick/commit/5ecd5b047cee7ccfe4e14a733a0755c7b2a90c7d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gwj6-pm7x-3r63"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106569","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder allow a crafted ASE image to cause a crash or a long-running operation. This issue is fixed in version 7.1.2-32."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106572","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106572","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106572","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106572","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106572","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a missing recursion-depth check in the CALS decoder allows a crafted CALS image to exhaust the call stack and terminate the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-106572","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106572","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106572","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/19bce64e3667ff03","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wxw6-98rj-hjfr","https://github.com/ImageMagick/ImageMagick6/commit/0ca580238abba18910cfee0fcc3159621fec0dee","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106572","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a missing recursion-depth check in the CALS decoder allows a crafted CALS image to exhaust the call stack and terminate the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106573","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106573","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106573","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106573","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106573","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing limit check in the MVG decoder allows a crafted MVG image to trigger an excessively long-running operation. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106573","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106573","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106573","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/c311471c4e4978494834c707b417bc033d95cc48","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qr53-hc3p-fc62","https://github.com/ImageMagick/ImageMagick6/commit/49560a1641f72a127e413b9861eca0997fde2b96","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106573","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing limit check in the MVG decoder allows a crafted MVG image to trigger an excessively long-running operation. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106568","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106568","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106568","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106568","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106568","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted XMP profile embedded in an image can cause the profile parser to enter an infinite loop, preventing image processing from completing. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."},"relatedVulnerabilities":[{"id":"CVE-2026-106568","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106568","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106568","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/e4f7ad983df6c831832eba3689f96b75f8b67051","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9p7q-63hw-mcr4","https://github.com/ImageMagick/ImageMagick6/commit/27e36ca5cb446664bfc284d28d91fced8887b025","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-57"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106568","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32 and 6.9.13-57, a crafted XMP profile embedded in an image can cause the profile parser to enter an infinite loop, preventing image processing from completing. This issue is fixed in versions 7.1.2-32 and 6.9.13-57."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106569","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106569","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106569","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106569","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106569","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106569","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder allow a crafted ASE image to cause a crash or a long-running operation. This issue is fixed in version 7.1.2-32."},"relatedVulnerabilities":[{"id":"CVE-2026-106569","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106569","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106569","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106569","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/0691546106f4c7e8857da9f21a0e4a8f41915388","https://github.com/ImageMagick/ImageMagick/commit/5ecd5b047cee7ccfe4e14a733a0755c7b2a90c7d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gwj6-pm7x-3r63"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106569","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder allow a crafted ASE image to cause a crash or a long-running operation. This issue is fixed in version 7.1.2-32."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106572","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106572","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106572","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106572","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106572","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a missing recursion-depth check in the CALS decoder allows a crafted CALS image to exhaust the call stack and terminate the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-106572","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106572","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106572","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/19bce64e3667ff03","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wxw6-98rj-hjfr","https://github.com/ImageMagick/ImageMagick6/commit/0ca580238abba18910cfee0fcc3159621fec0dee","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106572","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a missing recursion-depth check in the CALS decoder allows a crafted CALS image to exhaust the call stack and terminate the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106573","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106573","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106573","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106573","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"risk":0.19776,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106573","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing limit check in the MVG decoder allows a crafted MVG image to trigger an excessively long-running operation. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106573","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106573","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106573","date":"2026-10-08","epss":0.00384,"percentile":0.30341}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/c311471c4e4978494834c707b417bc033d95cc48","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qr53-hc3p-fc62","https://github.com/ImageMagick/ImageMagick6/commit/49560a1641f72a127e413b9861eca0997fde2b96","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106573","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing limit check in the MVG decoder allows a crafted MVG image to trigger an excessively long-running operation. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42528","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42528","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"risk":0.19343999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.  Users are recommended to upgrade to version 2.4.69, which fixes this issue"},"relatedVulnerabilities":[{"id":"CVE-2026-42528","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/12"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue"}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42528","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42528","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"risk":0.19343999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.  Users are recommended to upgrade to version 2.4.69, which fixes this issue"},"relatedVulnerabilities":[{"id":"CVE-2026-42528","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/12"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue"}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42528","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42528","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"risk":0.19343999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.  Users are recommended to upgrade to version 2.4.69, which fixes this issue"},"relatedVulnerabilities":[{"id":"CVE-2026-42528","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/12"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue"}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42528","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42528","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"risk":0.19343999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.  Users are recommended to upgrade to version 2.4.69, which fixes this issue"},"relatedVulnerabilities":[{"id":"CVE-2026-42528","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/12"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue"}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106564","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106564","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106564","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106564","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106564","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"risk":0.19158,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106564","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, a crafted EXR image can cause the EXR decoder to write beyond a heap buffer, causing the process to crash. This issue is fixed in version 7.1.2-32."},"relatedVulnerabilities":[{"id":"CVE-2026-106564","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106564","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106564","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106564","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f7437ebafcd92d6959eca4086d80b150d52bdb7c","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-54rx-5x9g-g465"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106564","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, a crafted EXR image can cause the EXR decoder to write beyond a heap buffer, causing the process to crash. This issue is fixed in version 7.1.2-32."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106575","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106575","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106575","cwe":"CWE-775","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106575","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"risk":0.19158,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106575","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted Magick script can cause an opened file pointer to remain unclosed, allowing repeated processing to exhaust available file descriptors. This issue is fixed in version 7.1.2-31."},"relatedVulnerabilities":[{"id":"CVE-2026-106575","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106575","cwe":"CWE-775","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106575","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/86672a16cedbf5a06d64e629e058310d683bb48e","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2w4h-697j-4vrm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106575","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted Magick script can cause an opened file pointer to remain unclosed, allowing repeated processing to exhaust available file descriptors. This issue is fixed in version 7.1.2-31."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106564","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106564","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106564","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106564","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106564","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"risk":0.19158,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106564","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, a crafted EXR image can cause the EXR decoder to write beyond a heap buffer, causing the process to crash. This issue is fixed in version 7.1.2-32."},"relatedVulnerabilities":[{"id":"CVE-2026-106564","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106564","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106564","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106564","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f7437ebafcd92d6959eca4086d80b150d52bdb7c","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-54rx-5x9g-g465"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106564","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, a crafted EXR image can cause the EXR decoder to write beyond a heap buffer, causing the process to crash. This issue is fixed in version 7.1.2-32."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106575","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106575","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106575","cwe":"CWE-775","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106575","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"risk":0.19158,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106575","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted Magick script can cause an opened file pointer to remain unclosed, allowing repeated processing to exhaust available file descriptors. This issue is fixed in version 7.1.2-31."},"relatedVulnerabilities":[{"id":"CVE-2026-106575","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106575","cwe":"CWE-775","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106575","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/86672a16cedbf5a06d64e629e058310d683bb48e","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2w4h-697j-4vrm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106575","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted Magick script can cause an opened file pointer to remain unclosed, allowing repeated processing to exhaust available file descriptors. This issue is fixed in version 7.1.2-31."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106564","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106564","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106564","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106564","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106564","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"risk":0.19158,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106564","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, a crafted EXR image can cause the EXR decoder to write beyond a heap buffer, causing the process to crash. This issue is fixed in version 7.1.2-32."},"relatedVulnerabilities":[{"id":"CVE-2026-106564","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106564","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106564","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106564","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f7437ebafcd92d6959eca4086d80b150d52bdb7c","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-54rx-5x9g-g465"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106564","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, a crafted EXR image can cause the EXR decoder to write beyond a heap buffer, causing the process to crash. This issue is fixed in version 7.1.2-32."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106575","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106575","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106575","cwe":"CWE-775","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106575","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"risk":0.19158,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106575","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted Magick script can cause an opened file pointer to remain unclosed, allowing repeated processing to exhaust available file descriptors. This issue is fixed in version 7.1.2-31."},"relatedVulnerabilities":[{"id":"CVE-2026-106575","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106575","cwe":"CWE-775","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106575","date":"2026-10-08","epss":0.00372,"percentile":0.29018}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/86672a16cedbf5a06d64e629e058310d683bb48e","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2w4h-697j-4vrm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106575","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted Magick script can cause an opened file pointer to remain unclosed, allowing repeated processing to exhaust available file descriptors. This issue is fixed in version 7.1.2-31."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106576","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106576","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106576","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106576","cwe":"CWE-834","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106576","date":"2026-10-08","epss":0.00372,"percentile":0.29017}],"risk":0.19158,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106576","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted XMP profile can trigger excessive work while the parser determines a rational value's numerator and denominator, causing denial of service. This issue is fixed in version 7.1.2-31."},"relatedVulnerabilities":[{"id":"CVE-2026-106576","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106576","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106576","cwe":"CWE-834","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106576","date":"2026-10-08","epss":0.00372,"percentile":0.29017}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f491576297141ff685dc4460d811986f5b6b6cec","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v45j-x8p4-3mh4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106576","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted XMP profile can trigger excessive work while the parser determines a rational value's numerator and denominator, causing denial of service. This issue is fixed in version 7.1.2-31."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106576","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106576","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106576","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106576","cwe":"CWE-834","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106576","date":"2026-10-08","epss":0.00372,"percentile":0.29017}],"risk":0.19158,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106576","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted XMP profile can trigger excessive work while the parser determines a rational value's numerator and denominator, causing denial of service. This issue is fixed in version 7.1.2-31."},"relatedVulnerabilities":[{"id":"CVE-2026-106576","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106576","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106576","cwe":"CWE-834","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106576","date":"2026-10-08","epss":0.00372,"percentile":0.29017}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f491576297141ff685dc4460d811986f5b6b6cec","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v45j-x8p4-3mh4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106576","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted XMP profile can trigger excessive work while the parser determines a rational value's numerator and denominator, causing denial of service. This issue is fixed in version 7.1.2-31."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106576","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106576","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106576","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106576","cwe":"CWE-834","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106576","date":"2026-10-08","epss":0.00372,"percentile":0.29017}],"risk":0.19158,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106576","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted XMP profile can trigger excessive work while the parser determines a rational value's numerator and denominator, causing denial of service. This issue is fixed in version 7.1.2-31."},"relatedVulnerabilities":[{"id":"CVE-2026-106576","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106576","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106576","cwe":"CWE-834","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106576","date":"2026-10-08","epss":0.00372,"percentile":0.29017}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/f491576297141ff685dc4460d811986f5b6b6cec","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v45j-x8p4-3mh4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106576","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a crafted XMP profile can trigger excessive work while the parser determines a rational value's numerator and denominator, causing denial of service. This issue is fixed in version 7.1.2-31."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"risk":0.18966000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2003-1580","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2003-1580","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2003-1580","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1580","date":"2026-10-08","epss":0.03709,"percentile":0.89461}],"risk":0.18545,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2003-1580","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."},"relatedVulnerabilities":[{"id":"CVE-2003-1580","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2003-1580","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1580","date":"2026-10-08","epss":0.03709,"percentile":0.89461}],"urls":["http://www.securityfocus.com/archive/1/313867"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2003-1580","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2003-1580","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2003-1580","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2003-1580","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1580","date":"2026-10-08","epss":0.03709,"percentile":0.89461}],"risk":0.18545,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2003-1580","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."},"relatedVulnerabilities":[{"id":"CVE-2003-1580","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2003-1580","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1580","date":"2026-10-08","epss":0.03709,"percentile":0.89461}],"urls":["http://www.securityfocus.com/archive/1/313867"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2003-1580","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2003-1580","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2003-1580","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2003-1580","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1580","date":"2026-10-08","epss":0.03709,"percentile":0.89461}],"risk":0.18545,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2003-1580","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."},"relatedVulnerabilities":[{"id":"CVE-2003-1580","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2003-1580","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1580","date":"2026-10-08","epss":0.03709,"percentile":0.89461}],"urls":["http://www.securityfocus.com/archive/1/313867"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2003-1580","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2003-1580","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2003-1580","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2003-1580","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1580","date":"2026-10-08","epss":0.03709,"percentile":0.89461}],"risk":0.18545,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2003-1580","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."},"relatedVulnerabilities":[{"id":"CVE-2003-1580","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2003-1580","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1580","date":"2026-10-08","epss":0.03709,"percentile":0.89461}],"urls":["http://www.securityfocus.com/archive/1/313867"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2003-1580","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2014-8166","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2014-8166","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2014-8166","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-8166","date":"2026-10-08","epss":0.03703,"percentile":0.8945}],"risk":0.18515,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2014-8166","description":"The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name."},"relatedVulnerabilities":[{"id":"CVE-2014-8166","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","metrics":{"baseScore":5.1,"impactScore":6.5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2014-8166","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2014-8166","date":"2026-10-08","epss":0.03703,"percentile":0.8945}],"urls":["http://www.openwall.com/lists/oss-security/2015/03/24/15","http://www.openwall.com/lists/oss-security/2015/03/24/2","http://www.securityfocus.com/bid/73300","https://bugzilla.redhat.com/show_bug.cgi?id=1084577"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2014-8166","description":"The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87875","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-87875","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87875","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-87875","date":"2026-10-08","epss":0.00392,"percentile":0.31212}],"risk":0.18228,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-87875","description":"The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content."},"relatedVulnerabilities":[{"id":"CVE-2026-87875","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87875","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-87875","date":"2026-10-08","epss":0.00392,"percentile":0.31212}],"urls":["https://access.redhat.com/errata/RHSA-2026:66600","https://access.redhat.com/security/cve/CVE-2026-87875","https://bugzilla.redhat.com/show_bug.cgi?id=2530994","https://github.com/OpenPrinting/cups/commit/0c6842fc615e8afa284136a092da8178abf5f142","https://github.com/OpenPrinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4","https://github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87875","description":"The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content."}]},{"artifact":{"id":"f192cb8dc63f3eb4","cpes":["cpe:2.3:a:cpp-14:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"cpp-14","purl":"pkg:deb/debian/cpp-14@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/cpp-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/cpp-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/cpp-14.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"1580254f2d5cda2a","cpes":["cpe:2.3:a:cpp-14-x86-64-linux-gnu:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux-gnu:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux_gnu:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux_gnu:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"cpp-14-x86-64-linux-gnu","purl":"pkg:deb/debian/cpp-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/cpp-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"bf427850ceb9b9cf","cpes":["cpe:2.3:a:g\\+\\+-14:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"g++-14","purl":"pkg:deb/debian/g%2B%2B-14@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/g++-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/g++-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/g++-14.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"64cb91ba3690d600","cpes":["cpe:2.3:a:g\\+\\+-14-x86-64-linux-gnu:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux-gnu:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux_gnu:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux_gnu:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"g++-14-x86-64-linux-gnu","purl":"pkg:deb/debian/g%2B%2B-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/g++-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"1753e0ab4835d319","cpes":["cpe:2.3:a:gcc-14:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14","purl":"pkg:deb/debian/gcc-14@14.2.0-19?arch=amd64&distro=debian-13.7","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/gcc-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/gcc-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/gcc-14.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"8a928cc6733b8d4c","cpes":["cpe:2.3:a:gcc-14-base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-base","purl":"pkg:deb/debian/gcc-14-base@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/gcc-14-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"afc74f4635aa2de5","cpes":["cpe:2.3:a:gcc-14-x86-64-linux-gnu:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux-gnu:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux_gnu:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux_gnu:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-x86-64-linux-gnu","purl":"pkg:deb/debian/gcc-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/gcc-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"7475a27907fe4420","cpes":["cpe:2.3:a:libasan8:libasan8:14.2.0-19:*:*:*:*:*:*:*"],"name":"libasan8","purl":"pkg:deb/debian/libasan8@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libasan8/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasan8:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libasan8:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"4aef59838e786012","cpes":["cpe:2.3:a:libatomic1:libatomic1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libatomic1","purl":"pkg:deb/debian/libatomic1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libatomic1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"062249237978e3de","cpes":["cpe:2.3:a:libcc1-0:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1-0:libcc1_0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1_0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1_0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libcc1-0","purl":"pkg:deb/debian/libcc1-0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libcc1-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"ef5dd5e55126a732","cpes":["cpe:2.3:a:libgcc-14-dev:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14-dev:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14_dev:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14_dev:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-14-dev","purl":"pkg:deb/debian/libgcc-14-dev@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libgcc-14-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-14-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libgcc-14-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"2338ed612a82adf3","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"71d32d5417d636ce","cpes":["cpe:2.3:a:libgomp1:libgomp1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgomp1","purl":"pkg:deb/debian/libgomp1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libgomp1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"81d0f863177c4ff2","cpes":["cpe:2.3:a:libhwasan0:libhwasan0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libhwasan0","purl":"pkg:deb/debian/libhwasan0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libhwasan0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhwasan0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libhwasan0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"30ada6cb82fd6f02","cpes":["cpe:2.3:a:libitm1:libitm1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libitm1","purl":"pkg:deb/debian/libitm1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libitm1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libitm1:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libitm1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"d3f0e91aac2169e5","cpes":["cpe:2.3:a:liblsan0:liblsan0:14.2.0-19:*:*:*:*:*:*:*"],"name":"liblsan0","purl":"pkg:deb/debian/liblsan0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/liblsan0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"2e7766dcd5ecb5f3","cpes":["cpe:2.3:a:libquadmath0:libquadmath0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libquadmath0","purl":"pkg:deb/debian/libquadmath0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libquadmath0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"0f0a43dbd793abf5","cpes":["cpe:2.3:a:libstdc\\+\\+-14-dev:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14-dev:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14_dev:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14_dev:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++-14-dev","purl":"pkg:deb/debian/libstdc%2B%2B-14-dev@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libstdc++-14-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++-14-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libstdc++-14-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"7dc961cf921ecd08","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"3faa4e2eb1e6610c","cpes":["cpe:2.3:a:libtsan2:libtsan2:14.2.0-19:*:*:*:*:*:*:*"],"name":"libtsan2","purl":"pkg:deb/debian/libtsan2@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libtsan2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"79fd96516c7017fa","cpes":["cpe:2.3:a:libubsan1:libubsan1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libubsan1","purl":"pkg:deb/debian/libubsan1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libubsan1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102635","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102635","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102635","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102635","date":"2026-10-08","epss":0.00319,"percentile":0.22867}],"risk":0.18023499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102635","description":"ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information."},"relatedVulnerabilities":[{"id":"CVE-2026-102635","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102635","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102635","date":"2026-10-08","epss":0.00319,"percentile":0.22867}],"urls":["https://github.com/ImageMagick/ImageMagick","https://github.com/ImageMagick/ImageMagick/blob/7.1.2-31/coders/gif.c#L1168-L1196","https://github.com/ImageMagick/ImageMagick/commit/a0ca2c739c0216ff4efbd631d1ba7fd54dba1ff4","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvv7-5mh8-vcfc","https://github.com/ImageMagick/ImageMagick6/commit/95dc0fd21a684bfac2bdb6fb6638c0ab271adbe5","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-32-and-6.9.13-57-uninitialized-heap-memory-disclosure-in-gif-decoder"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102635","description":"ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102635","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102635","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102635","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102635","date":"2026-10-08","epss":0.00319,"percentile":0.22867}],"risk":0.18023499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102635","description":"ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information."},"relatedVulnerabilities":[{"id":"CVE-2026-102635","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102635","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102635","date":"2026-10-08","epss":0.00319,"percentile":0.22867}],"urls":["https://github.com/ImageMagick/ImageMagick","https://github.com/ImageMagick/ImageMagick/blob/7.1.2-31/coders/gif.c#L1168-L1196","https://github.com/ImageMagick/ImageMagick/commit/a0ca2c739c0216ff4efbd631d1ba7fd54dba1ff4","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvv7-5mh8-vcfc","https://github.com/ImageMagick/ImageMagick6/commit/95dc0fd21a684bfac2bdb6fb6638c0ab271adbe5","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-32-and-6.9.13-57-uninitialized-heap-memory-disclosure-in-gif-decoder"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102635","description":"ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102635","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102635","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102635","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102635","date":"2026-10-08","epss":0.00319,"percentile":0.22867}],"risk":0.18023499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102635","description":"ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information."},"relatedVulnerabilities":[{"id":"CVE-2026-102635","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102635","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102635","date":"2026-10-08","epss":0.00319,"percentile":0.22867}],"urls":["https://github.com/ImageMagick/ImageMagick","https://github.com/ImageMagick/ImageMagick/blob/7.1.2-31/coders/gif.c#L1168-L1196","https://github.com/ImageMagick/ImageMagick/commit/a0ca2c739c0216ff4efbd631d1ba7fd54dba1ff4","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvv7-5mh8-vcfc","https://github.com/ImageMagick/ImageMagick6/commit/95dc0fd21a684bfac2bdb6fb6638c0ab271adbe5","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-32-and-6.9.13-57-uninitialized-heap-memory-disclosure-in-gif-decoder"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102635","description":"ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information."}]},{"artifact":{"id":"de3bcbf9daefbcfb","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/debian/libnghttp2-14@1.64.0-1.1%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=nghttp2","type":"deb","version":"1.64.0-1.1+deb13u1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58055","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"nghttp2","version":"1.64.0-1.1+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58055","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-08","epss":0.00319,"percentile":0.22818}],"risk":0.18023499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-58055","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-08","epss":0.00319,"percentile":0.22818}],"urls":["https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc","https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e","https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."}]},{"artifact":{"id":"0fa9072a5bfd36b6","cpes":["cpe:2.3:a:libsasl2-2:libsasl2-2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-2:libsasl2_2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2-2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_2:libsasl2_2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_2:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*"],"name":"libsasl2-2","purl":"pkg:deb/debian/libsasl2-2@2.1.28%2Bdfsg1-9?arch=amd64&distro=debian-13.7&upstream=cyrus-sasl2","type":"deb","version":"2.1.28+dfsg1-9","language":"","licenses":["BSD-2-clause","BSD-2.2-clause","BSD-3-Clause-Attribution","BSD-3-clause","BSD-3-clause-JANET","BSD-3-clause-PADL","BSD-4-clause-UC","FSFULLR","GPL-3","GPL-3+","IBM-as-is","MIT-CMU","MIT-Export","MIT-OpenVision","OpenLDAP","RSA-MD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-2/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libsasl2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libsasl2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cyrus-sasl2","version":"2.1.28+dfsg1-9"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"risk":0.17850000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."},"relatedVulnerabilities":[{"id":"CVE-2026-107161","cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"urls":["https://access.redhat.com/security/cve/CVE-2026-107161","https://bugzilla.redhat.com/show_bug.cgi?id=2460420"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."}]},{"artifact":{"id":"175bd219d71968b9","cpes":["cpe:2.3:a:libsasl2-modules-db:libsasl2-modules-db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules-db:libsasl2_modules_db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2-modules-db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules_db:libsasl2_modules_db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2-modules-db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2-modules:libsasl2_modules_db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2-modules-db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2_modules:libsasl2_modules_db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2-modules-db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*","cpe:2.3:a:libsasl2:libsasl2_modules_db:2.1.28\\+dfsg1-9:*:*:*:*:*:*:*"],"name":"libsasl2-modules-db","purl":"pkg:deb/debian/libsasl2-modules-db@2.1.28%2Bdfsg1-9?arch=amd64&distro=debian-13.7&upstream=cyrus-sasl2","type":"deb","version":"2.1.28+dfsg1-9","language":"","licenses":["BSD-2-clause","BSD-2.2-clause","BSD-3-Clause-Attribution","BSD-3-clause","BSD-3-clause-JANET","BSD-3-clause-PADL","BSD-4-clause-UC","FSFULLR","GPL-3","GPL-3+","IBM-as-is","MIT-CMU","MIT-Export","MIT-OpenVision","OpenLDAP","RSA-MD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsasl2-modules-db/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libsasl2-modules-db/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libsasl2-modules-db:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cyrus-sasl2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cyrus-sasl2","version":"2.1.28+dfsg1-9"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"risk":0.17850000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."},"relatedVulnerabilities":[{"id":"CVE-2026-107161","cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"urls":["https://access.redhat.com/security/cve/CVE-2026-107161","https://bugzilla.redhat.com/show_bug.cgi?id=2460420"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106577","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106577","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106577","cwe":"CWE-94","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106577","date":"2026-10-08","epss":0.00344,"percentile":0.25844}],"risk":0.17715999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106577","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code into output generated by PostScript coders. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106577","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106577","cwe":"CWE-94","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106577","date":"2026-10-08","epss":0.00344,"percentile":0.25844}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2ba2edfd04a1ab3d45af4a0dc1e640dde7020192","https://github.com/ImageMagick/ImageMagick/commit/78378cd623468760bee82a5930cb3011725916f8","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5rg6-j44q-q892","https://github.com/ImageMagick/ImageMagick6/commit/879489740daa44dd72e9405b26c845e8aa3d2f53","https://github.com/ImageMagick/ImageMagick6/commit/d5750d7309ef5a8cd561430d932a183e4168f484","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106577","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code into output generated by PostScript coders. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106577","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106577","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106577","cwe":"CWE-94","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106577","date":"2026-10-08","epss":0.00344,"percentile":0.25844}],"risk":0.17715999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106577","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code into output generated by PostScript coders. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106577","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106577","cwe":"CWE-94","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106577","date":"2026-10-08","epss":0.00344,"percentile":0.25844}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2ba2edfd04a1ab3d45af4a0dc1e640dde7020192","https://github.com/ImageMagick/ImageMagick/commit/78378cd623468760bee82a5930cb3011725916f8","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5rg6-j44q-q892","https://github.com/ImageMagick/ImageMagick6/commit/879489740daa44dd72e9405b26c845e8aa3d2f53","https://github.com/ImageMagick/ImageMagick6/commit/d5750d7309ef5a8cd561430d932a183e4168f484","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106577","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code into output generated by PostScript coders. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106577","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106577","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106577","cwe":"CWE-94","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106577","date":"2026-10-08","epss":0.00344,"percentile":0.25844}],"risk":0.17715999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106577","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code into output generated by PostScript coders. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-106577","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106577","cwe":"CWE-94","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106577","date":"2026-10-08","epss":0.00344,"percentile":0.25844}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2ba2edfd04a1ab3d45af4a0dc1e640dde7020192","https://github.com/ImageMagick/ImageMagick/commit/78378cd623468760bee82a5930cb3011725916f8","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5rg6-j44q-q892","https://github.com/ImageMagick/ImageMagick6/commit/879489740daa44dd72e9405b26c845e8aa3d2f53","https://github.com/ImageMagick/ImageMagick6/commit/d5750d7309ef5a8cd561430d932a183e4168f484","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106577","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code into output generated by PostScript coders. This issue is fixed in versions 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93590","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93590","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93590","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93590","date":"2026-10-08","epss":0.00312,"percentile":0.22101}],"risk":0.17627999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93590","description":"ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation."},"relatedVulnerabilities":[{"id":"CVE-2026-93590","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93590","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93590","date":"2026-10-08","epss":0.00312,"percentile":0.22101}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8cm","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-policy-bypass-in-uhdr-encoder"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93590","description":"ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93590","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93590","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93590","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93590","date":"2026-10-08","epss":0.00312,"percentile":0.22101}],"risk":0.17627999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93590","description":"ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation."},"relatedVulnerabilities":[{"id":"CVE-2026-93590","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93590","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93590","date":"2026-10-08","epss":0.00312,"percentile":0.22101}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8cm","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-policy-bypass-in-uhdr-encoder"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93590","description":"ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93590","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93590","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93590","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93590","date":"2026-10-08","epss":0.00312,"percentile":0.22101}],"risk":0.17627999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93590","description":"ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation."},"relatedVulnerabilities":[{"id":"CVE-2026-93590","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93590","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93590","date":"2026-10-08","epss":0.00312,"percentile":0.22101}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8cm","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-policy-bypass-in-uhdr-encoder"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93590","description":"ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"f5152615a12aeb3d","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"5c8cb5d5c2e5df78","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"bd4b70ba8c48d583","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"cfe9c78846143096","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"a6e51e84db754048","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"faedc3139e685610","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"9db9d188fa9e89fc","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:4.16.0-2+really2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"bd55752b0f187487","cpes":["cpe:2.3:a:mount:mount:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"166978fa81223e72","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107209","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107209","cwe":"CWE-415","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107209","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107209","date":"2026-10-08","epss":0.00315,"percentile":0.22457}],"risk":0.17167500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107209","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-107209","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107209","cwe":"CWE-415","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107209","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107209","date":"2026-10-08","epss":0.00315,"percentile":0.22457}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/326451aae51ac2dabc99fe66e063de6ec14cf8c8","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f2r2-qw7g-3c8x","https://github.com/ImageMagick/ImageMagick6/commit/04a4c5b89c034cf2c93bb0a10044332d941b4fa5","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107209","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107209","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107209","cwe":"CWE-415","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107209","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107209","date":"2026-10-08","epss":0.00315,"percentile":0.22457}],"risk":0.17167500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107209","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-107209","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107209","cwe":"CWE-415","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107209","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107209","date":"2026-10-08","epss":0.00315,"percentile":0.22457}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/326451aae51ac2dabc99fe66e063de6ec14cf8c8","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f2r2-qw7g-3c8x","https://github.com/ImageMagick/ImageMagick6/commit/04a4c5b89c034cf2c93bb0a10044332d941b4fa5","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107209","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107209","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107209","cwe":"CWE-415","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107209","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107209","date":"2026-10-08","epss":0.00315,"percentile":0.22457}],"risk":0.17167500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107209","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-107209","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107209","cwe":"CWE-415","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107209","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107209","date":"2026-10-08","epss":0.00315,"percentile":0.22457}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/326451aae51ac2dabc99fe66e063de6ec14cf8c8","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f2r2-qw7g-3c8x","https://github.com/ImageMagick/ImageMagick6/commit/04a4c5b89c034cf2c93bb0a10044332d941b4fa5","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107209","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"50f3e6307c72b0b7","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24401","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24401","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24401","date":"2026-10-08","epss":0.00296,"percentile":0.20454}],"risk":0.17019999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24401","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524."},"relatedVulnerabilities":[{"id":"CVE-2026-24401","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24401","date":"2026-10-08","epss":0.00296,"percentile":0.20454}],"urls":["https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524","https://github.com/avahi/avahi/issues/501","https://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24401","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524."}]},{"artifact":{"id":"e0cedc6dccd6380c","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24401","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24401","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24401","date":"2026-10-08","epss":0.00296,"percentile":0.20454}],"risk":0.17019999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24401","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524."},"relatedVulnerabilities":[{"id":"CVE-2026-24401","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24401","date":"2026-10-08","epss":0.00296,"percentile":0.20454}],"urls":["https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524","https://github.com/avahi/avahi/issues/501","https://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24401","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524."}]},{"artifact":{"id":"f8b8769b671bcd56","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24401","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24401","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24401","date":"2026-10-08","epss":0.00296,"percentile":0.20454}],"risk":0.17019999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24401","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524."},"relatedVulnerabilities":[{"id":"CVE-2026-24401","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24401","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24401","date":"2026-10-08","epss":0.00296,"percentile":0.20454}],"urls":["https://github.com/avahi/avahi/commit/78eab31128479f06e30beb8c1cbf99dd921e2524","https://github.com/avahi/avahi/issues/501","https://github.com/avahi/avahi/security/advisories/GHSA-h4vp-5m8j-f6w3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24401","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical name point to the same domain (e.g., \"h.local\" as a CNAME for \"h.local\"). This causes unbounded recursion in the lookup_handle_cname function, leading to stack exhaustion. The vulnerability affects record browsers where AVAHI_LOOKUP_USE_MULTICAST is set explicitly, which includes record browsers created by resolvers used by nss-mdns. This issue is patched in commit 78eab31128479f06e30beb8c1cbf99dd921e2524."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107210","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107210","cwe":"CWE-409","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107210","date":"2026-10-08","epss":0.00321,"percentile":0.23092}],"risk":0.16531500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107210","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted highly compressed MAT image can make the MAT decoder create temporary files larger than the configured security-policy limit, bypassing resource restrictions and consuming excessive disk space. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-107210","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107210","cwe":"CWE-409","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107210","date":"2026-10-08","epss":0.00321,"percentile":0.23092}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ae2ed8c81d8fad1f186e7f2bc0837b46a1c7be61","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3j4w-pvxj-fpjc","https://github.com/ImageMagick/ImageMagick6/commit/7d8e0eb11804a5ce5322ea317dfd3557cded4e7b","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107210","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted highly compressed MAT image can make the MAT decoder create temporary files larger than the configured security-policy limit, bypassing resource restrictions and consuming excessive disk space. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107210","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107210","cwe":"CWE-409","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107210","date":"2026-10-08","epss":0.00321,"percentile":0.23092}],"risk":0.16531500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107210","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted highly compressed MAT image can make the MAT decoder create temporary files larger than the configured security-policy limit, bypassing resource restrictions and consuming excessive disk space. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-107210","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107210","cwe":"CWE-409","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107210","date":"2026-10-08","epss":0.00321,"percentile":0.23092}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ae2ed8c81d8fad1f186e7f2bc0837b46a1c7be61","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3j4w-pvxj-fpjc","https://github.com/ImageMagick/ImageMagick6/commit/7d8e0eb11804a5ce5322ea317dfd3557cded4e7b","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107210","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted highly compressed MAT image can make the MAT decoder create temporary files larger than the configured security-policy limit, bypassing resource restrictions and consuming excessive disk space. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107210","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107210","cwe":"CWE-409","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107210","date":"2026-10-08","epss":0.00321,"percentile":0.23092}],"risk":0.16531500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107210","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted highly compressed MAT image can make the MAT decoder create temporary files larger than the configured security-policy limit, bypassing resource restrictions and consuming excessive disk space. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-107210","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107210","cwe":"CWE-409","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107210","date":"2026-10-08","epss":0.00321,"percentile":0.23092}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ae2ed8c81d8fad1f186e7f2bc0837b46a1c7be61","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3j4w-pvxj-fpjc","https://github.com/ImageMagick/ImageMagick6/commit/7d8e0eb11804a5ce5322ea317dfd3557cded4e7b","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107210","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted highly compressed MAT image can make the MAT decoder create temporary files larger than the configured security-policy limit, bypassing resource restrictions and consuming excessive disk space. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-08","epss":0.03249,"percentile":0.8796}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93589","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93589","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93589","cwe":"CWE-369","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93589","date":"2026-10-08","epss":0.00285,"percentile":0.19301}],"risk":0.161025,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93589","description":"ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-93589","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93589","cwe":"CWE-369","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93589","date":"2026-10-08","epss":0.00285,"percentile":0.19301}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4gg2-hfgh-6f5c","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-division-by-zero-in-flif-encoder"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93589","description":"ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93589","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93589","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93589","cwe":"CWE-369","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93589","date":"2026-10-08","epss":0.00285,"percentile":0.19301}],"risk":0.161025,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93589","description":"ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-93589","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93589","cwe":"CWE-369","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93589","date":"2026-10-08","epss":0.00285,"percentile":0.19301}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4gg2-hfgh-6f5c","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-division-by-zero-in-flif-encoder"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93589","description":"ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93589","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93589","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93589","cwe":"CWE-369","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93589","date":"2026-10-08","epss":0.00285,"percentile":0.19301}],"risk":0.161025,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93589","description":"ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56."},"relatedVulnerabilities":[{"id":"CVE-2026-93589","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93589","cwe":"CWE-369","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93589","date":"2026-10-08","epss":0.00285,"percentile":0.19301}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4gg2-hfgh-6f5c","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-31-division-by-zero-in-flif-encoder"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93589","description":"ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-08","epss":0.03193,"percentile":0.87729}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42356","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42356","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"risk":0.15745,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.    This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-42356","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/11"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42356","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42356","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"risk":0.15745,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.    This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-42356","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/11"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42356","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42356","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"risk":0.15745,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.    This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-42356","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/11"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42356","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42356","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"risk":0.15745,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.    This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-42356","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/11"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107208","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107208","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107208","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107208","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107208","date":"2026-10-08","epss":0.00302,"percentile":0.20994}],"risk":0.15553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107208","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a recursion limit that is handled as a fatal condition instead of an ordinary exception, terminating the image-processing process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-107208","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107208","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107208","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107208","date":"2026-10-08","epss":0.00302,"percentile":0.20994}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/907b74817836b4f88e7453f0e95c849a1c5311aa","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-27m9-54jx-fgvq","https://github.com/ImageMagick/ImageMagick6/commit/6ba345f88a14fcce35c723c231914ae054c4281a","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107208","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a recursion limit that is handled as a fatal condition instead of an ordinary exception, terminating the image-processing process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107208","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107208","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107208","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107208","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107208","date":"2026-10-08","epss":0.00302,"percentile":0.20994}],"risk":0.15553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107208","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a recursion limit that is handled as a fatal condition instead of an ordinary exception, terminating the image-processing process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-107208","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107208","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107208","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107208","date":"2026-10-08","epss":0.00302,"percentile":0.20994}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/907b74817836b4f88e7453f0e95c849a1c5311aa","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-27m9-54jx-fgvq","https://github.com/ImageMagick/ImageMagick6/commit/6ba345f88a14fcce35c723c231914ae054c4281a","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107208","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a recursion limit that is handled as a fatal condition instead of an ordinary exception, terminating the image-processing process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107208","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-107208","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107208","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107208","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107208","date":"2026-10-08","epss":0.00302,"percentile":0.20994}],"risk":0.15553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-107208","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a recursion limit that is handled as a fatal condition instead of an ordinary exception, terminating the image-processing process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."},"relatedVulnerabilities":[{"id":"CVE-2026-107208","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107208","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-107208","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-107208","date":"2026-10-08","epss":0.00302,"percentile":0.20994}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/907b74817836b4f88e7453f0e95c849a1c5311aa","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-27m9-54jx-fgvq","https://github.com/ImageMagick/ImageMagick6/commit/6ba345f88a14fcce35c723c231914ae054c4281a","https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107208","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, a crafted XMP profile can reach a recursion limit that is handled as a fatal condition instead of an ordinary exception, terminating the image-processing process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55."}]},{"artifact":{"id":"367a8ef1674ed188","cpes":["cpe:2.3:a:apache2:apache2:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2","purl":"pkg:deb/debian/apache2@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.conffiles","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.list"},{"path":"/var/lib/dpkg/info/apache2.postinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postinst"},{"path":"/var/lib/dpkg/info/apache2.postrm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.postrm"},{"path":"/var/lib/dpkg/info/apache2.preinst","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.preinst"},{"path":"/var/lib/dpkg/info/apache2.prerm","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2003-1581","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2003-1581","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2003-1581","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1581","date":"2026-10-08","epss":0.0308,"percentile":0.87293}],"risk":0.15400000000000003,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2003-1581","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."},"relatedVulnerabilities":[{"id":"CVE-2003-1581","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2003-1581","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1581","date":"2026-10-08","epss":0.0308,"percentile":0.87293}],"urls":["http://www.securityfocus.com/archive/1/313867"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2003-1581","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."}]},{"artifact":{"id":"8020a14e02485a5c","cpes":["cpe:2.3:a:apache2-bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_bin:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_bin:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-bin","purl":"pkg:deb/debian/apache2-bin@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-bin/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-bin.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-bin.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2003-1581","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2003-1581","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2003-1581","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1581","date":"2026-10-08","epss":0.0308,"percentile":0.87293}],"risk":0.15400000000000003,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2003-1581","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."},"relatedVulnerabilities":[{"id":"CVE-2003-1581","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2003-1581","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1581","date":"2026-10-08","epss":0.0308,"percentile":0.87293}],"urls":["http://www.securityfocus.com/archive/1/313867"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2003-1581","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."}]},{"artifact":{"id":"5fa307db7ff01a67","cpes":["cpe:2.3:a:apache2-data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_data:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_data:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-data","purl":"pkg:deb/debian/apache2-data@2.4.68-1~deb13u1?arch=all&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-data/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-data.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-data.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2003-1581","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2003-1581","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2003-1581","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1581","date":"2026-10-08","epss":0.0308,"percentile":0.87293}],"risk":0.15400000000000003,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2003-1581","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."},"relatedVulnerabilities":[{"id":"CVE-2003-1581","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2003-1581","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1581","date":"2026-10-08","epss":0.0308,"percentile":0.87293}],"urls":["http://www.securityfocus.com/archive/1/313867"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2003-1581","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2003-1581","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2003-1581","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2003-1581","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1581","date":"2026-10-08","epss":0.0308,"percentile":0.87293}],"risk":0.15400000000000003,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2003-1581","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."},"relatedVulnerabilities":[{"id":"CVE-2003-1581","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2003-1581","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1581","date":"2026-10-08","epss":0.0308,"percentile":0.87293}],"urls":["http://www.securityfocus.com/archive/1/313867"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2003-1581","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-9114","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2016-9114","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-9114","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9114","date":"2026-10-08","epss":0.03077,"percentile":0.87282}],"risk":0.15385,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9114","description":"There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service."},"relatedVulnerabilities":[{"id":"CVE-2016-9114","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-9114","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9114","date":"2026-10-08","epss":0.03077,"percentile":0.87282}],"urls":["http://www.securityfocus.com/bid/93979","https://github.com/uclouvain/openjpeg/issues/857","https://security.gentoo.org/glsa/201710-26"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9114","description":"There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-9113","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2016-9113","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-9113","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9113","date":"2026-10-08","epss":0.0305,"percentile":0.87175}],"risk":0.1525,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9113","description":"There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service."},"relatedVulnerabilities":[{"id":"CVE-2016-9113","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-9113","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9113","date":"2026-10-08","epss":0.0305,"percentile":0.87175}],"urls":["http://www.securityfocus.com/bid/93980","https://github.com/uclouvain/openjpeg/issues/856","https://security.gentoo.org/glsa/201710-26"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9113","description":"There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-08","epss":0.03044,"percentile":0.87139}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"ea4018933b7b4ef6","cpes":["cpe:2.3:a:libx11-6:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-6:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*"],"name":"libx11-6","purl":"pkg:deb/debian/libx11-6@2%3A1.8.12-1?arch=amd64&distro=debian-13.7&upstream=libx11","type":"deb","version":"2:1.8.12-1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-6/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libx11-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-88806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libx11","version":"2:1.8.12-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-88806","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"risk":0.14925,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."},"relatedVulnerabilities":[{"id":"CVE-2026-88806","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."}]},{"artifact":{"id":"25c33176f8e0362a","cpes":["cpe:2.3:a:libx11-data:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-data:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*"],"name":"libx11-data","purl":"pkg:deb/debian/libx11-data@2%3A1.8.12-1?arch=all&distro=debian-13.7&upstream=libx11","type":"deb","version":"2:1.8.12-1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-data/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libx11-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libx11-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.list","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libx11-data.list"}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-88806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libx11","version":"2:1.8.12-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-88806","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"risk":0.14925,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."},"relatedVulnerabilities":[{"id":"CVE-2026-88806","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."}]},{"artifact":{"id":"65d9e9ce270d33b1","cpes":["cpe:2.3:a:libjbig0:libjbig0:2.1-6.1\\+b2:*:*:*:*:*:*:*"],"name":"libjbig0","purl":"pkg:deb/debian/libjbig0@2.1-6.1%2Bb2?arch=amd64&distro=debian-13.7&upstream=jbigkit%402.1-6.1","type":"deb","version":"2.1-6.1+b2","language":"","licenses":["GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjbig0/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libjbig0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjbig0:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libjbig0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jbigkit","version":"2.1-6.1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-9937","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"jbigkit","version":"2.1-6.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2017-9937","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-9937","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9937","date":"2026-10-08","epss":0.02962,"percentile":0.86811}],"risk":0.1481,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-9937","description":"In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack."},"relatedVulnerabilities":[{"id":"CVE-2017-9937","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-9937","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-9937","date":"2026-10-08","epss":0.02962,"percentile":0.86811}],"urls":["http://bugzilla.maptools.org/show_bug.cgi?id=2707","http://www.securityfocus.com/bid/99304","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-9937","description":"In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack."}]},{"artifact":{"id":"eaa0fe7eb7a30a90","cpes":["cpe:2.3:a:m4:m4:1.4.19-8:*:*:*:*:*:*:*"],"name":"m4","purl":"pkg:deb/debian/m4@1.4.19-8?arch=amd64&distro=debian-13.7","type":"deb","version":"1.4.19-8","language":"","licenses":["sha256:9438e0cbd4cf2121d2a9b61f42b1aaf765788dc3454983c55f2107cfe504f11c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/m4/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/m4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/m4.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/m4.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/m4.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/m4.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2008-1688","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"m4","version":"1.4.19-8"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-1688","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2008-1688","date":"2026-10-08","epss":0.02957,"percentile":0.86786}],"risk":0.14785,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-1688","description":"Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option.  NOTE: it is not clear when this issue crosses privilege boundaries."},"relatedVulnerabilities":[{"id":"CVE-2008-1688","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2008-1688","date":"2026-10-08","epss":0.02957,"percentile":0.86786}],"urls":["http://osvdb.org/44272","http://secunia.com/advisories/29671","http://secunia.com/advisories/29729","http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.510612","http://www.openwall.com/lists/oss-security/2008/04/07/1","http://www.openwall.com/lists/oss-security/2008/04/07/3","http://www.securityfocus.com/bid/28688","http://www.vupen.com/english/advisories/2008/1151/references","https://exchange.xforce.ibmcloud.com/vulnerabilities/41704"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-1688","description":"Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option.  NOTE: it is not clear when this issue crosses privilege boundaries."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27447","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27447","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.3,"impactScore":4.3,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27447","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-27447","date":"2026-10-08","epss":0.0026,"percentile":0.162}],"risk":0.14689999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27447","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches."},"relatedVulnerabilities":[{"id":"CVE-2026-27447","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.3,"impactScore":4.3,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":4.3,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27447","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-27447","date":"2026-10-08","epss":0.0026,"percentile":0.162}],"urls":["https://github.com/OpenPrinting/cups/commit/88516bf6d9e34cef7a64a704b856b837f70cd220","https://github.com/OpenPrinting/cups/security/advisories/GHSA-v987-m8hp-phj9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27447","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches."}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86143","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86143","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256}],"risk":0.14356,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86143","description":"In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback."},"relatedVulnerabilities":[{"id":"CVE-2026-86143","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256}],"urls":["https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86143","description":"In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback."}]},{"artifact":{"id":"f5152615a12aeb3d","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"5c8cb5d5c2e5df78","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"bd4b70ba8c48d583","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"cfe9c78846143096","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"a6e51e84db754048","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"faedc3139e685610","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"9db9d188fa9e89fc","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:4.16.0-2+really2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"bd55752b0f187487","cpes":["cpe:2.3:a:mount:mount:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"166978fa81223e72","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86144","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86144","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"risk":0.14229000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86144","description":"In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow)."},"relatedVulnerabilities":[{"id":"CVE-2026-86144","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"urls":["https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86144","description":"In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow)."}]},{"artifact":{"id":"893ab677af71bedc","cpes":["cpe:2.3:a:login.defs:login.defs:1\\:4.17.4-2:*:*:*:*:*:*:*"],"name":"login.defs","purl":"pkg:deb/debian/login.defs@1%3A4.17.4-2?arch=all&distro=debian-13.7&upstream=shadow","type":"deb","version":"1:4.17.4-2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login.defs/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/login.defs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.postinst"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.14057999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"a0c2eaa9ca5431ff","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.17.4-2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/debian/passwd@1%3A4.17.4-2?arch=amd64&distro=debian-13.7&upstream=shadow","type":"deb","version":"1:4.17.4-2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.14057999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34990","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34990","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34990","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34990","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"risk":0.13923,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34990","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token is enough to drive /admin/ requests on localhost, and the attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to persist a file:///... queue even though the normal FileDevice policy rejects such URIs. Printing to that queue gives an arbitrary root file overwrite; the PoC below uses that primitive to drop a sudoers fragment and demonstrate root command execution. At time of publication, there are no publicly available patches."},"relatedVulnerabilities":[{"id":"CVE-2026-34990","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34990","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34990","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-c54j-2vqw-wpwp"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34990","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token is enough to drive /admin/ requests on localhost, and the attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to persist a file:///... queue even though the normal FileDevice policy rejects such URIs. Printing to that queue gives an arbitrary root file overwrite; the PoC below uses that primitive to drop a sudoers fragment and demonstrate root command execution. At time of publication, there are no publicly available patches."}]},{"artifact":{"id":"e9d28bf4fecb65b4","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"8d18bdf2d28de8c0","cpes":["cpe:2.3:a:perl:perl:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"1ed310f43f3fc66d","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"ec18de78d97e6b78","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6%2Bdeb13u1?arch=all&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"7a21ed9bbad10f4c","cpes":["cpe:2.3:a:binutils:binutils:2.44-3:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/debian/binutils@2.44-3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.conffiles","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/binutils.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/binutils.list"},{"path":"/var/lib/dpkg/info/binutils.preinst","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/binutils.preinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"bf5ed39a2bba44c5","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.44-3:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/debian/binutils-common@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"b048185e7cf16adc","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"36f20bcb4ff2650f","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.44-3:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/debian/libbinutils@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"b0a949b30d35d392","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.44-3:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/debian/libctf-nobfd0@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"820e67ebcb63a2a2","cpes":["cpe:2.3:a:libctf0:libctf0:2.44-3:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/debian/libctf0@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"77edfb107040a28c","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.44-3:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/debian/libgprofng0@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"9c03630d3a75e45e","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.44-3:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/debian/libsframe1@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-08","epss":0.02675,"percentile":0.85354}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-16376","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-16376","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-16376","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16376","date":"2026-10-08","epss":0.02647,"percentile":0.85168}],"risk":0.13235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-16376","description":"An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact."},"relatedVulnerabilities":[{"id":"CVE-2018-16376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-16376","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-16376","date":"2026-10-08","epss":0.02647,"percentile":0.85168}],"urls":["http://www.securityfocus.com/bid/105262","https://github.com/uclouvain/openjpeg/issues/1127"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-16376","description":"An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-08","epss":0.02633,"percentile":0.85093}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-9117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2016-9117","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-9117","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9117","date":"2026-10-08","epss":0.02558,"percentile":0.84611}],"risk":0.12789999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9117","description":"NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file."},"relatedVulnerabilities":[{"id":"CVE-2016-9117","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-9117","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9117","date":"2026-10-08","epss":0.02558,"percentile":0.84611}],"urls":["http://www.securityfocus.com/bid/93783","https://github.com/uclouvain/openjpeg/issues/860","https://security.gentoo.org/glsa/201710-26"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9117","description":"NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.1276,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39328","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-39328","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39328","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39328","date":"2026-10-08","epss":0.00242,"percentile":0.14156}],"risk":0.12705,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-39328","description":"A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file."},"relatedVulnerabilities":[{"id":"CVE-2023-39328","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39328","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39328","date":"2026-10-08","epss":0.00242,"percentile":0.14156}],"urls":["https://access.redhat.com/security/cve/CVE-2023-39328","https://bugzilla.redhat.com/show_bug.cgi?id=2219236","https://github.com/uclouvain/openjpeg/issues/1476","https://github.com/uclouvain/openjpeg/pull/1470","https://github.com/uclouvain/openjpeg/pull/1471"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39328","description":"A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file."}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86139","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86139","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86139","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86139","date":"2026-10-08","epss":0.00166,"percentile":0.05341}],"risk":0.12699,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86139","description":"In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-86139","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86139","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86139","date":"2026-10-08","epss":0.00166,"percentile":0.05341}],"urls":["https://github.com/GNOME/libxml2/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86139","description":"In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow."}]},{"artifact":{"id":"614dd2dfa62b9595","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.7&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap2/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libldap2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15719","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2020-15719","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-08","epss":0.02515,"percentile":0.84338}],"risk":0.12575,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."},"relatedVulnerabilities":[{"id":"CVE-2020-15719","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-08","epss":0.02515,"percentile":0.84338}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00033.html","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00059.html","https://access.redhat.com/errata/RHBA-2019:3674","https://bugs.openldap.org/show_bug.cgi?id=9266","https://bugzilla.redhat.com/show_bug.cgi?id=1740070","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."}]},{"artifact":{"id":"eaa0fe7eb7a30a90","cpes":["cpe:2.3:a:m4:m4:1.4.19-8:*:*:*:*:*:*:*"],"name":"m4","purl":"pkg:deb/debian/m4@1.4.19-8?arch=amd64&distro=debian-13.7","type":"deb","version":"1.4.19-8","language":"","licenses":["sha256:9438e0cbd4cf2121d2a9b61f42b1aaf765788dc3454983c55f2107cfe504f11c"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/m4/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/m4/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/m4.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/m4.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/m4.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/m4.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2008-1687","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"m4","version":"1.4.19-8"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-1687","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-1687","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-1687","date":"2026-10-08","epss":0.0245,"percentile":0.83895}],"risk":0.12250000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-1687","description":"The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename."},"relatedVulnerabilities":[{"id":"CVE-2008-1687","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-1687","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-1687","date":"2026-10-08","epss":0.0245,"percentile":0.83895}],"urls":["http://secunia.com/advisories/29671","http://secunia.com/advisories/29729","http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.510612","http://www.openwall.com/lists/oss-security/2008/04/07/1","http://www.openwall.com/lists/oss-security/2008/04/07/12","http://www.openwall.com/lists/oss-security/2008/04/07/3","http://www.openwall.com/lists/oss-security/2008/04/07/4","http://www.securityfocus.com/bid/28688","http://www.vupen.com/english/advisories/2008/1151/references","https://exchange.xforce.ibmcloud.com/vulnerabilities/41706"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-1687","description":"The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-08","epss":0.02447,"percentile":0.83872}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-58436","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-58436","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58436","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-58436","date":"2026-10-08","epss":0.0023,"percentile":0.1274}],"risk":0.12075,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-58436","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15."},"relatedVulnerabilities":[{"id":"CVE-2025-58436","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.1,"impactScore":3.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58436","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-58436","date":"2026-10-08","epss":0.0023,"percentile":0.1274}],"urls":["https://github.com/OpenPrinting/cups/commit/40008d76a001babbb9beb9d9d74b01a86fb6ddb4","https://github.com/OpenPrinting/cups/releases/tag/v2.4.15","https://github.com/OpenPrinting/cups/security/advisories/GHSA-8wpw-vfgm-qrrr","http://www.openwall.com/lists/oss-security/2025/11/27/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58436","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15."}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86140","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86140","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86140","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86140","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"risk":0.12010499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86140","description":"In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-86140","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":8,"impactScore":5.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86140","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86140","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86140","description":"In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow."}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86142","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86142","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231}],"risk":0.12010499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86142","description":"In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation."},"relatedVulnerabilities":[{"id":"CVE-2026-86142","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231}],"urls":["https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86142","description":"In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"f5152615a12aeb3d","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"5c8cb5d5c2e5df78","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"bd4b70ba8c48d583","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"cfe9c78846143096","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"a6e51e84db754048","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"faedc3139e685610","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"9db9d188fa9e89fc","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:4.16.0-2+really2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"bd55752b0f187487","cpes":["cpe:2.3:a:mount:mount:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"166978fa81223e72","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"87a086ab1a842620","cpes":["cpe:2.3:a:ghostscript:ghostscript:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*"],"name":"ghostscript","purl":"pkg:deb/debian/ghostscript@10.05.1~dfsg-1%2Bdeb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"10.05.1~dfsg-1+deb13u2","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ghostscript/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/ghostscript/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ghostscript.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/ghostscript.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ghostscript.list","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/ghostscript.list"},{"path":"/var/lib/dpkg/info/ghostscript.postinst","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/ghostscript.postinst"},{"path":"/var/lib/dpkg/info/ghostscript.prerm","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/ghostscript.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-101258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ghostscript","version":"10.05.1~dfsg-1+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-101258","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"risk":0.11551499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."},"relatedVulnerabilities":[{"id":"CVE-2026-101258","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"urls":["https://access.redhat.com/security/cve/CVE-2026-101258","https://bugzilla.redhat.com/show_bug.cgi?id=2542396","https://github.com/v12-security/pocs/tree/main/ghostscript"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."}]},{"artifact":{"id":"3c7a92703086b14e","cpes":["cpe:2.3:a:libgs-common:libgs-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs-common:libgs_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*"],"name":"libgs-common","purl":"pkg:deb/debian/libgs-common@10.05.1~dfsg-1%2Bdeb13u2?arch=all&distro=debian-13.7&upstream=ghostscript","type":"deb","version":"10.05.1~dfsg-1+deb13u2","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs-common/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libgs-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libgs-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.list","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libgs-common.list"}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-101258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ghostscript","version":"10.05.1~dfsg-1+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-101258","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"risk":0.11551499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."},"relatedVulnerabilities":[{"id":"CVE-2026-101258","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"urls":["https://access.redhat.com/security/cve/CVE-2026-101258","https://bugzilla.redhat.com/show_bug.cgi?id=2542396","https://github.com/v12-security/pocs/tree/main/ghostscript"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."}]},{"artifact":{"id":"750235da747ba01e","cpes":["cpe:2.3:a:libgs10:libgs10:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*"],"name":"libgs10","purl":"pkg:deb/debian/libgs10@10.05.1~dfsg-1%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=ghostscript","type":"deb","version":"10.05.1~dfsg-1+deb13u2","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libgs10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libgs10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-101258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ghostscript","version":"10.05.1~dfsg-1+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-101258","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"risk":0.11551499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."},"relatedVulnerabilities":[{"id":"CVE-2026-101258","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"urls":["https://access.redhat.com/security/cve/CVE-2026-101258","https://bugzilla.redhat.com/show_bug.cgi?id=2542396","https://github.com/v12-security/pocs/tree/main/ghostscript"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."}]},{"artifact":{"id":"33e5c936ca2d2a4a","cpes":["cpe:2.3:a:libgs10-common:libgs10-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs10-common:libgs10_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10-common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10_common:10.05.1\\~dfsg-1\\+deb13u2:*:*:*:*:*:*:*"],"name":"libgs10-common","purl":"pkg:deb/debian/libgs10-common@10.05.1~dfsg-1%2Bdeb13u2?arch=all&distro=debian-13.7&upstream=ghostscript","type":"deb","version":"10.05.1~dfsg-1+deb13u2","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10-common/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libgs10-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libgs10-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.list","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libgs10-common.list"}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-101258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ghostscript","version":"10.05.1~dfsg-1+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-101258","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"risk":0.11551499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."},"relatedVulnerabilities":[{"id":"CVE-2026-101258","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"urls":["https://access.redhat.com/security/cve/CVE-2026-101258","https://bugzilla.redhat.com/show_bug.cgi?id=2542396","https://github.com/v12-security/pocs/tree/main/ghostscript"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."}]},{"artifact":{"id":"ea4018933b7b4ef6","cpes":["cpe:2.3:a:libx11-6:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-6:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*"],"name":"libx11-6","purl":"pkg:deb/debian/libx11-6@2%3A1.8.12-1?arch=amd64&distro=debian-13.7&upstream=libx11","type":"deb","version":"2:1.8.12-1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-6/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libx11-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94283","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libx11","version":"2:1.8.12-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-94283","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"risk":0.11442499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."},"relatedVulnerabilities":[{"id":"CVE-2026-94283","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"25c33176f8e0362a","cpes":["cpe:2.3:a:libx11-data:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-data:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*"],"name":"libx11-data","purl":"pkg:deb/debian/libx11-data@2%3A1.8.12-1?arch=all&distro=debian-13.7&upstream=libx11","type":"deb","version":"2:1.8.12-1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-data/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libx11-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libx11-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.list","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libx11-data.list"}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94283","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libx11","version":"2:1.8.12-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-94283","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"risk":0.11442499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."},"relatedVulnerabilities":[{"id":"CVE-2026-94283","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-08","epss":0.02267,"percentile":0.825}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"21af26782f8669a0","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/debian/libp11-kit0@0.25.5-3?arch=amd64&distro=debian-13.7&upstream=p11-kit","type":"deb","version":"0.25.5-3","language":"","licenses":["Apache-2.0","BSD-3-clause","FSFAP","FSFULLR","GPL-2+","GPL-3+","ISC","LGPL-2.1","LGPL-2.1+","X11","customFSFUL","customFSFULLRWD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13757","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"p11-kit","version":"0.25.5-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13757","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-08","epss":0.00202,"percentile":0.09262}],"risk":0.11312000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."},"relatedVulnerabilities":[{"id":"CVE-2026-13757","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-08","epss":0.00202,"percentile":0.09262}],"urls":["https://access.redhat.com/errata/RHSA-2026:37469","https://access.redhat.com/errata/RHSA-2026:38342","https://access.redhat.com/errata/RHSA-2026:49667","https://access.redhat.com/errata/RHSA-2026:49668","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54387","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2026-13757","https://bugzilla.redhat.com/show_bug.cgi?id=2494556","https://github.com/advisories/GHSA-p2wm-69qx-x25w"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-9116","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2016-9116","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-9116","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9116","date":"2026-10-08","epss":0.02236,"percentile":0.8227}],"risk":0.11180000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9116","description":"NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file."},"relatedVulnerabilities":[{"id":"CVE-2016-9116","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-9116","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9116","date":"2026-10-08","epss":0.02236,"percentile":0.8227}],"urls":["http://www.securityfocus.com/bid/93975","https://github.com/uclouvain/openjpeg/issues/859","https://security.gentoo.org/glsa/201710-26"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9116","description":"NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file."}]},{"artifact":{"id":"0af6f2d3417a318d","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-2\\+b1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/debian/libacl1@2.3.2-2%2Bb1?arch=amd64&distro=debian-13.7&upstream=acl%402.3.2-2","type":"deb","version":"2.3.2-2+b1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl","version":"2.3.2-2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"acl","version":"2.3.2-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.11168999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"f5152615a12aeb3d","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"5c8cb5d5c2e5df78","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"bd4b70ba8c48d583","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"cfe9c78846143096","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"a6e51e84db754048","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"faedc3139e685610","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"9db9d188fa9e89fc","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:4.16.0-2+really2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"bd55752b0f187487","cpes":["cpe:2.3:a:mount:mount:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"166978fa81223e72","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86137","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86137","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86137","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86137","date":"2026-10-08","epss":0.00195,"percentile":0.08398}],"risk":0.10822499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86137","description":"In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp."},"relatedVulnerabilities":[{"id":"CVE-2026-86137","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86137","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86137","date":"2026-10-08","epss":0.00195,"percentile":0.08398}],"urls":["https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86137","description":"In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-10505","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2016-10505","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-10505","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-10505","date":"2026-10-08","epss":0.02149,"percentile":0.81564}],"risk":0.10744999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-10505","description":"NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files."},"relatedVulnerabilities":[{"id":"CVE-2016-10505","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-10505","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-10505","date":"2026-10-08","epss":0.02149,"percentile":0.81564}],"urls":["https://github.com/uclouvain/openjpeg/issues/776","https://github.com/uclouvain/openjpeg/issues/784","https://github.com/uclouvain/openjpeg/issues/785","https://github.com/uclouvain/openjpeg/issues/792","https://security.gentoo.org/glsa/201710-26"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-10505","description":"NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"risk":0.106575,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2008-3134","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-3134","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-3134","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3134","date":"2026-10-08","epss":0.02127,"percentile":0.81375}],"risk":0.10635,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-3134","description":"Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file."},"relatedVulnerabilities":[{"id":"CVE-2008-3134","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-3134","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3134","date":"2026-10-08","epss":0.02127,"percentile":0.81375}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00004.html","http://secunia.com/advisories/30879","http://secunia.com/advisories/32151","http://sourceforge.net/forum/forum.php?forum_id=841176","http://sourceforge.net/project/shownotes.php?release_id=610253","http://www.securityfocus.com/bid/30055","http://www.securitytracker.com/id?1020413","http://www.vupen.com/english/advisories/2008/1984/references","https://exchange.xforce.ibmcloud.com/vulnerabilities/43511","https://exchange.xforce.ibmcloud.com/vulnerabilities/43513"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-3134","description":"Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2008-3134","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-3134","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-3134","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3134","date":"2026-10-08","epss":0.02127,"percentile":0.81375}],"risk":0.10635,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-3134","description":"Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file."},"relatedVulnerabilities":[{"id":"CVE-2008-3134","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-3134","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3134","date":"2026-10-08","epss":0.02127,"percentile":0.81375}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00004.html","http://secunia.com/advisories/30879","http://secunia.com/advisories/32151","http://sourceforge.net/forum/forum.php?forum_id=841176","http://sourceforge.net/project/shownotes.php?release_id=610253","http://www.securityfocus.com/bid/30055","http://www.securitytracker.com/id?1020413","http://www.vupen.com/english/advisories/2008/1984/references","https://exchange.xforce.ibmcloud.com/vulnerabilities/43511","https://exchange.xforce.ibmcloud.com/vulnerabilities/43513"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-3134","description":"Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2008-3134","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-3134","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-3134","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3134","date":"2026-10-08","epss":0.02127,"percentile":0.81375}],"risk":0.10635,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-3134","description":"Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file."},"relatedVulnerabilities":[{"id":"CVE-2008-3134","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-3134","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3134","date":"2026-10-08","epss":0.02127,"percentile":0.81375}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00004.html","http://secunia.com/advisories/30879","http://secunia.com/advisories/32151","http://sourceforge.net/forum/forum.php?forum_id=841176","http://sourceforge.net/project/shownotes.php?release_id=610253","http://www.securityfocus.com/bid/30055","http://www.securitytracker.com/id?1020413","http://www.vupen.com/english/advisories/2008/1984/references","https://exchange.xforce.ibmcloud.com/vulnerabilities/43511","https://exchange.xforce.ibmcloud.com/vulnerabilities/43513"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-3134","description":"Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-9115","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2016-9115","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-9115","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9115","date":"2026-10-08","epss":0.02118,"percentile":0.81286}],"risk":0.10590000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9115","description":"Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file."},"relatedVulnerabilities":[{"id":"CVE-2016-9115","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-9115","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9115","date":"2026-10-08","epss":0.02118,"percentile":0.81286}],"urls":["http://www.securityfocus.com/bid/93977","https://github.com/uclouvain/openjpeg/issues/858","https://security.gentoo.org/glsa/201710-26"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9115","description":"Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106574","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106574","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106574","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-131","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106574","date":"2026-10-08","epss":0.00201,"percentile":0.09186}],"risk":0.10351500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106574","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a client connected to the distributed pixel cache server can send crafted pixel data that triggers an integer-size calculation error and a heap buffer overwrite, crashing the server. This issue is fixed in version 7.1.2-31."},"relatedVulnerabilities":[{"id":"CVE-2026-106574","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106574","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-131","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106574","date":"2026-10-08","epss":0.00201,"percentile":0.09186}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/c69f54e1c8660e45f2ff83c354bf924a946d9356","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4fq9-vrx7-gv92"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106574","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a client connected to the distributed pixel cache server can send crafted pixel data that triggers an integer-size calculation error and a heap buffer overwrite, crashing the server. This issue is fixed in version 7.1.2-31."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106574","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106574","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106574","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-131","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106574","date":"2026-10-08","epss":0.00201,"percentile":0.09186}],"risk":0.10351500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106574","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a client connected to the distributed pixel cache server can send crafted pixel data that triggers an integer-size calculation error and a heap buffer overwrite, crashing the server. This issue is fixed in version 7.1.2-31."},"relatedVulnerabilities":[{"id":"CVE-2026-106574","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106574","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-131","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106574","date":"2026-10-08","epss":0.00201,"percentile":0.09186}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/c69f54e1c8660e45f2ff83c354bf924a946d9356","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4fq9-vrx7-gv92"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106574","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a client connected to the distributed pixel cache server can send crafted pixel data that triggers an integer-size calculation error and a heap buffer overwrite, crashing the server. This issue is fixed in version 7.1.2-31."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106574","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106574","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106574","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-131","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106574","date":"2026-10-08","epss":0.00201,"percentile":0.09186}],"risk":0.10351500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106574","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a client connected to the distributed pixel cache server can send crafted pixel data that triggers an integer-size calculation error and a heap buffer overwrite, crashing the server. This issue is fixed in version 7.1.2-31."},"relatedVulnerabilities":[{"id":"CVE-2026-106574","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106574","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-131","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-106574","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106574","date":"2026-10-08","epss":0.00201,"percentile":0.09186}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/c69f54e1c8660e45f2ff83c354bf924a946d9356","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4fq9-vrx7-gv92"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106574","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31, a client connected to the distributed pixel cache server can send crafted pixel data that triggers an integer-size calculation error and a heap buffer overwrite, crashing the server. This issue is fixed in version 7.1.2-31."}]},{"artifact":{"id":"daa1f8dfeee1793b","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"c5f7e9443917908e","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"0d7d9accbe1a77b1","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"dcbb71b238b6d3d6","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-08","epss":0.02049,"percentile":0.80637}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"7d303616b76e48ff","cpes":["cpe:2.3:a:libglib2.0-0t64:libglib2.0-0t64:2.84.4-3\\~deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0t64:libglib2.0_0t64:2.84.4-3\\~deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0-0t64:2.84.4-3\\~deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0_0t64:2.84.4-3\\~deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0t64:2.84.4-3\\~deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0t64:2.84.4-3\\~deb13u5:*:*:*:*:*:*:*"],"name":"libglib2.0-0t64","purl":"pkg:deb/debian/libglib2.0-0t64@2.84.4-3~deb13u5?arch=amd64&distro=debian-13.7&upstream=glib2.0","type":"deb","version":"2.84.4-3~deb13u5","language":"","licenses":["AFL-2.0","Apache-2.0","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MPL-1.1","Mingw-PD","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6","cmph","old-glib-tests"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0t64/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libglib2.0-0t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2012-0039","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glib2.0","version":"2.84.4-3~deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2012-0039","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2012-0039","cwe":"CWE-310","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2012-0039","date":"2026-10-08","epss":0.02043,"percentile":0.80572}],"risk":0.10215,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2012-0039","description":"GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application."},"relatedVulnerabilities":[{"id":"CVE-2012-0039","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2012-0039","cwe":"CWE-310","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2012-0039","date":"2026-10-08","epss":0.02043,"percentile":0.80572}],"urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=655044","http://mail.gnome.org/archives/gtk-devel-list/2003-May/msg00111.html","http://openwall.com/lists/oss-security/2012/01/10/12","https://bugzilla.redhat.com/show_bug.cgi?id=772720"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2012-0039","description":"GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-64685","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-64685","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64685","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-64685","date":"2026-10-08","epss":0.00198,"percentile":0.08692}],"risk":0.10197,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64685","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27."},"relatedVulnerabilities":[{"id":"CVE-2026-64685","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64685","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-64685","date":"2026-10-08","epss":0.00198,"percentile":0.08692}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7rgw-xg25-prjm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64685","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-64685","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-64685","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64685","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-64685","date":"2026-10-08","epss":0.00198,"percentile":0.08692}],"risk":0.10197,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64685","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27."},"relatedVulnerabilities":[{"id":"CVE-2026-64685","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64685","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-64685","date":"2026-10-08","epss":0.00198,"percentile":0.08692}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7rgw-xg25-prjm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64685","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-64685","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-64685","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64685","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-64685","date":"2026-10-08","epss":0.00198,"percentile":0.08692}],"risk":0.10197,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-64685","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27."},"relatedVulnerabilities":[{"id":"CVE-2026-64685","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-64685","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-64685","date":"2026-10-08","epss":0.00198,"percentile":0.08692}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7rgw-xg25-prjm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-64685","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-39316","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-39316","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39316","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-39316","date":"2026-10-08","epss":0.00182,"percentile":0.07133}],"risk":0.10192000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-39316","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a use-after-free vulnerability exists in the CUPS scheduler (cupsd) when temporary printers are automatically deleted. cupsdDeleteTemporaryPrinters() in scheduler/printers.c calls cupsdDeletePrinter() without first expiring subscriptions that reference the printer, leaving cupsd_subscription_t.dest as a dangling pointer to freed heap memory. The dangling pointer is subsequently dereferenced at multiple code sites, causing a crash (denial of service) of the cupsd daemon. With heap grooming, this can be leveraged for code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-39316","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39316","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-39316","date":"2026-10-08","epss":0.00182,"percentile":0.07133}],"urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-pjv5-prqp-46rg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39316","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a use-after-free vulnerability exists in the CUPS scheduler (cupsd) when temporary printers are automatically deleted. cupsdDeleteTemporaryPrinters() in scheduler/printers.c calls cupsdDeletePrinter() without first expiring subscriptions that reference the printer, leaving cupsd_subscription_t.dest as a dangling pointer to freed heap memory. The dangling pointer is subsequently dereferenced at multiple code sites, causing a crash (denial of service) of the cupsd daemon. With heap grooming, this can be leveraged for code execution."}]},{"artifact":{"id":"6f2066ac1c2128fd","cpes":["cpe:2.3:a:libattr1:libattr1:1\\:2.5.2-3:*:*:*:*:*:*:*"],"name":"libattr1","purl":"pkg:deb/debian/libattr1@1%3A2.5.2-3?arch=amd64&distro=debian-13.7&upstream=attr","type":"deb","version":"1:2.5.2-3","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libattr1/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libattr1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libattr1:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libattr1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"attr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"attr","version":"1:2.5.2-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54371","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-08","epss":0.00179,"percentile":0.06854}],"risk":0.10113499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54371","description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path."},"relatedVulnerabilities":[{"id":"CVE-2026-54371","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-08","epss":0.00179,"percentile":0.06854}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f","https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b","https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr","https://access.redhat.com/errata/RHSA-2026:34889","https://access.redhat.com/errata/RHSA-2026:56133","https://access.redhat.com/errata/RHSA-2026:59380","https://access.redhat.com/errata/RHSA-2026:60226","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/security/cve/CVE-2026-54371","https://bugzilla.redhat.com/show_bug.cgi?id=2490283","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54371","description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path."}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86138","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86138","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383}],"risk":0.10097999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86138","description":"In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-86138","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383}],"urls":["https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86138","description":"In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow."}]},{"artifact":{"id":"8a1ec6d9372df578","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.7&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27171","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"risk":0.10027499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."},"relatedVulnerabilities":[{"id":"CVE-2026-27171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-9580","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2016-9580","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-9580","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2016-9580","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2016-9580","cwe":"CWE-190","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9580","date":"2026-10-08","epss":0.01994,"percentile":0.80058}],"risk":0.09970000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9580","description":"An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2016-9580","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-9580","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2016-9580","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2016-9580","cwe":"CWE-190","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9580","date":"2026-10-08","epss":0.01994,"percentile":0.80058}],"urls":["http://www.securityfocus.com/bid/94822","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9580","https://github.com/szukw000/openjpeg/commit/cadff5fb6e73398de26a92e96d3d7cac893af255","https://github.com/uclouvain/openjpeg/issues/871","https://security.gentoo.org/glsa/201710-26"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9580","description":"An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow."}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87876","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-87876","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3,"impactScore":1.5,"exploitabilityScore":1.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87876","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-87876","date":"2026-10-08","epss":0.00328,"percentile":0.23841}],"risk":0.09839999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-87876","description":"Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations."},"relatedVulnerabilities":[{"id":"CVE-2026-87876","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3,"impactScore":1.5,"exploitabilityScore":1.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87876","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-87876","date":"2026-10-08","epss":0.00328,"percentile":0.23841}],"urls":["https://access.redhat.com/errata/RHSA-2026:67568","https://access.redhat.com/security/cve/CVE-2026-87876","https://bugzilla.redhat.com/show_bug.cgi?id=2530991","https://github.com/OpenPrinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8","https://github.com/OpenPrinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","https://github.com/OpenPrinting/cups/security/advisories/GHSA-r8jp-q6fh-g5r2"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87876","description":"Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"3747a63ebad1c96d","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.3-2.1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/debian/libopenjp2-7@2.5.3-2.1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openjpeg2","type":"deb","version":"2.5.3-2.1~deb13u2","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-9581","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openjpeg2","version":"2.5.3-2.1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2016-9581","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-9581","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2016-9581","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2016-9581","cwe":"CWE-119","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9581","date":"2026-10-08","epss":0.01944,"percentile":0.79547}],"risk":0.0972,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-9581","description":"An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2."},"relatedVulnerabilities":[{"id":"CVE-2016-9581","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-9581","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2016-9581","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2016-9581","cwe":"CWE-119","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-9581","date":"2026-10-08","epss":0.01944,"percentile":0.79547}],"urls":["http://www.securityfocus.com/bid/94822","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9581","https://github.com/szukw000/openjpeg/commit/cadff5fb6e73398de26a92e96d3d7cac893af255","https://github.com/uclouvain/openjpeg/issues/872","https://security.gentoo.org/glsa/201710-26"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-9581","description":"An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2."}]},{"artifact":{"id":"212a71fa16031fdf","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"7402a3d31bb024db","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"3f9378db54aaac9e","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"e96cb50e09a471e0","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"50f3e6307c72b0b7","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/debian/libavahi-client3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-59529","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"risk":0.093975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59529","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users."},"relatedVulnerabilities":[{"id":"CVE-2025-59529","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users."}]},{"artifact":{"id":"e0cedc6dccd6380c","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/debian/libavahi-common-data@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-59529","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"risk":0.093975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59529","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users."},"relatedVulnerabilities":[{"id":"CVE-2025-59529","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users."}]},{"artifact":{"id":"f8b8769b671bcd56","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-16:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-16:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/debian/libavahi-common3@0.8-16?arch=amd64&distro=debian-13.7&upstream=avahi","type":"deb","version":"0.8-16","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"avahi","version":"0.8-16"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-59529","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"risk":0.093975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-59529","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users."},"relatedVulnerabilities":[{"id":"CVE-2025-59529","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users."}]},{"artifact":{"id":"e2c0cfe2f366c89d","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u3:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u3?arch=amd64&distro=debian-13.7&upstream=tiff","type":"deb","version":"4.7.0-3+deb13u3","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-1210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tiff","version":"4.7.0-3+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2022-1210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-1210","cwe":"CWE-400","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2022-1210","cwe":"CWE-404","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1210","date":"2026-10-08","epss":0.01851,"percentile":0.78479}],"risk":0.09255,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-1210","description":"A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used."},"relatedVulnerabilities":[{"id":"CVE-2022-1210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1210","cwe":"CWE-400","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2022-1210","cwe":"CWE-404","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1210","date":"2026-10-08","epss":0.01851,"percentile":0.78479}],"urls":["https://gitlab.com/libtiff/libtiff/-/issues/402","https://gitlab.com/libtiff/libtiff/uploads/c3da94e53cf1e1e8e6d4d3780dc8c42f/example.tiff","https://security.gentoo.org/glsa/202210-10","https://security.netapp.com/advisory/ntap-20220513-0005/","https://vuldb.com/?id.196363"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1210","description":"A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used."}]},{"artifact":{"id":"e2c0cfe2f366c89d","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.7.0-3\\+deb13u3:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/debian/libtiff6@4.7.0-3%2Bdeb13u3?arch=amd64&distro=debian-13.7&upstream=tiff","type":"deb","version":"4.7.0-3+deb13u3","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-10126","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tiff","version":"4.7.0-3+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-10126","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-10126","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10126","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"risk":0.09145,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-10126","description":"ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c."},"relatedVulnerabilities":[{"id":"CVE-2018-10126","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-10126","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10126","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"urls":["http://bugzilla.maptools.org/show_bug.cgi?id=2786","https://gitlab.com/libtiff/libtiff/-/issues/128","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10126","description":"ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c."}]},{"artifact":{"id":"fcb706650c034eda","cpes":["cpe:2.3:a:libfreetype6:libfreetype6:2.13.3\\+dfsg-1\\+deb13u1:*:*:*:*:*:*:*"],"name":"libfreetype6","purl":"pkg:deb/debian/libfreetype6@2.13.3%2Bdfsg-1%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=freetype","type":"deb","version":"2.13.3+dfsg-1+deb13u1","language":"","licenses":["BSD-3-Clause","BSL-1.0","Expat","FSFAP","FTL","GPL-2","GPL-2+","GPL-3","GPL-3+","MIT-Modern-Variant","MIT-SMC","OpenGroup-MIT","Public-Domain","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libfreetype6/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libfreetype6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libfreetype6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"freetype"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95512","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"freetype","version":"2.13.3+dfsg-1+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95512","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"risk":0.09135,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95512","description":"A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate."},"relatedVulnerabilities":[{"id":"CVE-2026-95512","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95512","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95512","date":"2026-10-08","epss":0.00174,"percentile":0.06261}],"urls":["https://access.redhat.com/errata/RHSA-2026:74952","https://access.redhat.com/security/cve/CVE-2026-95512","https://bugzilla.redhat.com/show_bug.cgi?id=2462295","https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95512","description":"A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106570","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106570","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106570","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106570","date":"2026-10-08","epss":0.00194,"percentile":0.08344}],"risk":0.09021,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106570","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, an unauthenticated adjacent-network client can repeatedly connect to the distributed pixel cache server and exhaust its available connections, causing denial of service. This issue is fixed in version 7.1.2-32."},"relatedVulnerabilities":[{"id":"CVE-2026-106570","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106570","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106570","date":"2026-10-08","epss":0.00194,"percentile":0.08344}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/cafc7372c8113a9636766f0eddde7b90373c9b44","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2vwg-3g4g-qprm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106570","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, an unauthenticated adjacent-network client can repeatedly connect to the distributed pixel cache server and exhaust its available connections, causing denial of service. This issue is fixed in version 7.1.2-32."}]},{"artifact":{"id":"b442da9136764fed","cpes":["cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16-10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16_10:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_7.q16:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickcore-7.q16-10","purl":"pkg:deb/debian/libmagickcore-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickcore-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickcore-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106570","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106570","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106570","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106570","date":"2026-10-08","epss":0.00194,"percentile":0.08344}],"risk":0.09021,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106570","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, an unauthenticated adjacent-network client can repeatedly connect to the distributed pixel cache server and exhaust its available connections, causing denial of service. This issue is fixed in version 7.1.2-32."},"relatedVulnerabilities":[{"id":"CVE-2026-106570","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106570","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106570","date":"2026-10-08","epss":0.00194,"percentile":0.08344}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/cafc7372c8113a9636766f0eddde7b90373c9b44","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2vwg-3g4g-qprm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106570","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, an unauthenticated adjacent-network client can repeatedly connect to the distributed pixel cache server and exhaust its available connections, causing denial of service. This issue is fixed in version 7.1.2-32."}]},{"artifact":{"id":"88d485775f8770dc","cpes":["cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16-10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16_10:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_7.q16:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-7.q16-10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_7.q16_10:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"libmagickwand-7.q16-10","purl":"pkg:deb/debian/libmagickwand-7.q16-10@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=amd64&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-7.q16-10/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/libmagickwand-7.q16-10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/libmagickwand-7.q16-10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106570","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106570","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106570","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106570","date":"2026-10-08","epss":0.00194,"percentile":0.08344}],"risk":0.09021,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106570","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, an unauthenticated adjacent-network client can repeatedly connect to the distributed pixel cache server and exhaust its available connections, causing denial of service. This issue is fixed in version 7.1.2-32."},"relatedVulnerabilities":[{"id":"CVE-2026-106570","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106570","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-106570","date":"2026-10-08","epss":0.00194,"percentile":0.08344}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/cafc7372c8113a9636766f0eddde7b90373c9b44","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2vwg-3g4g-qprm"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106570","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, an unauthenticated adjacent-network client can repeatedly connect to the distributed pixel cache server and exhaust its available connections, causing denial of service. This issue is fixed in version 7.1.2-32."}]},{"artifact":{"id":"3ba9233cd9623220","cpes":["cpe:2.3:a:bzip2:bzip2:1.0.8-6:*:*:*:*:*:*:*"],"name":"bzip2","purl":"pkg:deb/debian/bzip2@1.0.8-6?arch=amd64&distro=debian-13.7","type":"deb","version":"1.0.8-6","language":"","licenses":["BSD-variant","GPL-2"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bzip2/copyright","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/usr/share/doc/bzip2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bzip2.md5sums","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/bzip2.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bzip2.list","layerID":"sha256:e22bc5d8b14ddc8f5372c02b3623a35e48ac205a30526761f7097904fdf9e82c","accessPath":"/var/lib/dpkg/info/bzip2.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"bzip2","version":"1.0.8-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42250","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"risk":0.08918,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).  This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"},"relatedVulnerabilities":[{"id":"CVE-2026-42250","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"}]},{"artifact":{"id":"6004b03bf692a003","cpes":["cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2-1.0:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*"],"name":"libbz2-1.0","purl":"pkg:deb/debian/libbz2-1.0@1.0.8-6?arch=amd64&distro=debian-13.7&upstream=bzip2","type":"deb","version":"1.0.8-6","language":"","licenses":["BSD-variant","GPL-2"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbz2-1.0/copyright","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/usr/share/doc/libbz2-1.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","layerID":"sha256:15f1c8eb1ab18eae260c7fb6296434cbe1ff0e1e30fd814ae92a80dd54005e62","accessPath":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bzip2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"bzip2","version":"1.0.8-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42250","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"risk":0.08918,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).  This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"},"relatedVulnerabilities":[{"id":"CVE-2026-42250","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"}]},{"artifact":{"id":"99df015a43949852","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.10-3\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/debian/libcups2t64@2.4.10-3%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=cups","type":"deb","version":"2.4.10-3+deb13u2","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:f6b146d093b89504da98e2dab5cd1680c34c1dd8e4963da38e6f4bcd4e2ad62f","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-39314","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"cups","version":"2.4.10-3+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-39314","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39314","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-39314","date":"2026-10-08","epss":0.00158,"percentile":0.04341}],"risk":0.08848000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-39314","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, an integer underflow vulnerability in _ppdCreateFromIPP() (cups/ppd-cache.c) allows any unprivileged local user to crash the cupsd root process by supplying a negative job-password-supported IPP attribute. The bounds check only caps the upper bound, so a negative value passes validation, is cast to size_t (wrapping to ~2^64), and is used as the length argument to memset() on a 33-byte stack buffer. This causes an immediate SIGSEGV in the cupsd root process. Combined with systemd's Restart=on-failure, an attacker can repeat the crash for sustained denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-39314","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39314","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-39314","date":"2026-10-08","epss":0.00158,"percentile":0.04341}],"urls":["https://github.com/OpenPrinting/cups/security/advisories/GHSA-pp8w-2g52-7vj7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39314","description":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, an integer underflow vulnerability in _ppdCreateFromIPP() (cups/ppd-cache.c) allows any unprivileged local user to crash the cupsd root process by supplying a negative job-password-supported IPP attribute. The bounds check only caps the upper bound, so a negative value passes validation, is cast to size_t (wrapping to ~2^64), and is used as the length argument to memset() on a 33-byte stack buffer. This causes an immediate SIGSEGV in the cupsd root process. Combined with systemd's Restart=on-failure, an attacker can repeat the crash for sustained denial of service."}]},{"artifact":{"id":"74e0d2fced48138b","cpes":["cpe:2.3:a:libxml2:libxml2:2.12.7\\+dfsg\\+really2.9.14-2.1\\+deb13u3:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/debian/libxml2@2.12.7%2Bdfsg%2Breally2.9.14-2.1%2Bdeb13u3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:67354b2996686891a49b9f7f75b06ef43d260c21c53afb933a122b96cffff620","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libxml2","version":"2.12.7+dfsg+really2.9.14-2.1+deb13u3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76781","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76781","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-76781","date":"2026-10-08","epss":0.00167,"percentile":0.05427}],"risk":0.087675,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76781","description":"A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-76781","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76781","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-76781","date":"2026-10-08","epss":0.00167,"percentile":0.05427}],"urls":["https://access.redhat.com/errata/RHSA-2026:57604","https://access.redhat.com/security/cve/CVE-2026-76781","https://bugzilla.redhat.com/show_bug.cgi?id=2519776","https://gitlab.gnome.org/GNOME/libxml2/-/commit/c6324894","https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/442"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76781","description":"A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS)."}]},{"artifact":{"id":"313023f42280be25","cpes":["cpe:2.3:a:imagemagick-7-common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7-common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7_common:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_7:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-7-common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_7_common:8\\:7.1.1.43\\+dfsg1-1\\+deb13u12:*:*:*:*:*:*:*"],"name":"imagemagick-7-common","purl":"pkg:deb/debian/imagemagick-7-common@8%3A7.1.1.43%2Bdfsg1-1%2Bdeb13u12?arch=all&distro=debian-13.7&upstream=imagemagick","type":"deb","version":"8:7.1.1.43+dfsg1-1+deb13u12","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-7-common/copyright","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/usr/share/doc/imagemagick-7-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-7-common.list","layerID":"sha256:09c10e23b8883ff2a399c6d3fe72caa55b5235ab896beab08756a980837dd800","accessPath":"/var/lib/dpkg/info/imagemagick-7-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-11754","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"imagemagick","version":"8:7.1.1.43+dfsg1-1+deb13u12"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2017-11754","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-11754","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-11754","date":"2026-10-08","epss":0.01743,"percentile":0.77074}],"risk":0.08715,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-11754","description":"The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an OpenPixelCache call."},"relatedVulnerabilities":[{"id":"CVE-2017-11754","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-11754","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-11754","date":"2026-10-08","epss":0.01743,"percentile":0.77074}],"urls":["https://github.com/ImageMagick/ImageMagick/issues/633"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-11754","description":"The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an OpenPixelCache call."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T23:25:22.083Z","grype_db_version":"2026-10-09T06:32:32.000Z"}