{"grype_matches":[{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-7264","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-7264","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"risk":7.179915,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-7264","description":"A flaw was found in libcurl, where libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If a syntactically incorrect field is given, the parser can use -1 for the length of the *time fraction*, leading to a `strlen()` performed on a pointer to a heap buffer area that is not purposely NULL terminated."},"relatedVulnerabilities":[{"id":"CVE-2024-7264","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/31/1","https://curl.se/docs/CVE-2024-7264.html","https://curl.se/docs/CVE-2024-7264.json","https://hackerone.com/reports/2629968","https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519","https://security.netapp.com/advisory/ntap-20240828-0008/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7264","description":"libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-7264","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-7264","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"risk":7.179915,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-7264","description":"A flaw was found in libcurl, where libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If a syntactically incorrect field is given, the parser can use -1 for the length of the *time fraction*, leading to a `strlen()` performed on a pointer to a heap buffer area that is not purposely NULL terminated."},"relatedVulnerabilities":[{"id":"CVE-2024-7264","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/31/1","https://curl.se/docs/CVE-2024-7264.html","https://curl.se/docs/CVE-2024-7264.json","https://hackerone.com/reports/2629968","https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519","https://security.netapp.com/advisory/ntap-20240828-0008/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7264","description":"libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used."}]},{"artifact":{"id":"e988ae274c693810","cpes":["cpe:2.3:a:redhat:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=tar-1.34-13.el9_8.src.rpm","type":"rpm","version":"2:1.34-13.el9_8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2005-2541","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"tar","version":"2:1.34-13.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2005-2541","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"risk":2.3951999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2005-2541","description":"A flaw was found in tar utility that can allow the root user to extract files with preserved setuid and setgid permissions without any warning. This behavior can lead to the creation of malicious setuid executables owned by root from a crafted tar file, posing significant security risks."},"relatedVulnerabilities":[{"id":"CVE-2005-2541","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"urls":["http://marc.info/?l=bugtraq&m=112327628230258&w=2","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-28388","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28388","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"risk":1.1129450000000003,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28388","description":"A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application."},"relatedVulnerabilities":[{"id":"CVE-2026-28388","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"urls":["https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e","https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139","https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3","https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8","https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28388","description":"Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28388","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28388","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"risk":1.1129450000000003,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28388","description":"A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application."},"relatedVulnerabilities":[{"id":"CVE-2026-28388","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"urls":["https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e","https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139","https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3","https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8","https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28388","description":"Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28388","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28388","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"risk":1.1129450000000003,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28388","description":"A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application."},"relatedVulnerabilities":[{"id":"CVE-2026-28388","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"urls":["https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e","https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139","https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3","https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8","https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28388","description":"Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-28389","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28389","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"risk":1.0835750000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28389","description":"A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data."},"relatedVulnerabilities":[{"id":"CVE-2026-28389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"urls":["https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5","https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616","https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f","https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a","https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28389","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28389","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28389","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"risk":1.0835750000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28389","description":"A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data."},"relatedVulnerabilities":[{"id":"CVE-2026-28389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"urls":["https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5","https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616","https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f","https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a","https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28389","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28389","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28389","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"risk":1.0835750000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28389","description":"A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data."},"relatedVulnerabilities":[{"id":"CVE-2026-28389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"urls":["https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5","https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616","https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f","https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a","https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28389","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"6b29b8ef2f83cc22","cpes":["cpe:2.3:a:redhat:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm","purl":"pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84837","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"0:4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-84837","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"risk":0.76736,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."},"relatedVulnerabilities":[{"id":"CVE-2026-84837","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"urls":["https://access.redhat.com/security/cve/CVE-2026-84837","https://bugzilla.redhat.com/show_bug.cgi?id=2478408"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."}]},{"artifact":{"id":"108e4bcd5f0cf305","cpes":["cpe:2.3:a:rpm-libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm-libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm-libs","purl":"pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.16.1.3-40.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84837","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-84837","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"risk":0.76736,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."},"relatedVulnerabilities":[{"id":"CVE-2026-84837","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"urls":["https://access.redhat.com/security/cve/CVE-2026-84837","https://bugzilla.redhat.com/show_bug.cgi?id=2478408"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-9681","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-9681","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9681","cwe":"CWE-697","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-9681","date":"2026-10-08","epss":0.01987,"percentile":0.79983}],"risk":0.6855149999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-9681","description":"A vulnerability was found in curl. When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than intended."},"relatedVulnerabilities":[{"id":"CVE-2024-9681","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9681","cwe":"CWE-697","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-9681","date":"2026-10-08","epss":0.01987,"percentile":0.79983}],"urls":["https://curl.se/docs/CVE-2024-9681.html","https://curl.se/docs/CVE-2024-9681.json","https://hackerone.com/reports/2764830","http://seclists.org/fulldisclosure/2025/Apr/10","http://seclists.org/fulldisclosure/2025/Apr/11","http://seclists.org/fulldisclosure/2025/Apr/12","http://seclists.org/fulldisclosure/2025/Apr/13","http://seclists.org/fulldisclosure/2025/Apr/4","http://seclists.org/fulldisclosure/2025/Apr/5","http://seclists.org/fulldisclosure/2025/Apr/8","http://seclists.org/fulldisclosure/2025/Apr/9","http://www.openwall.com/lists/oss-security/2024/11/06/2","https://security.netapp.com/advisory/ntap-20241213-0006/","https://github.com/curl/curl/commit/7385610d0c74c6a25","https://github.com/curl/curl/commit/a94973805df96269bf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-9681","description":"When curl is asked to use HSTS, the expiry time for a subdomain might\noverwrite a parent domain's cache entry, making it end sooner or later than\notherwise intended.\n\nThis affects curl using applications that enable HSTS and use URLs with the\ninsecure `HTTP://` scheme and perform transfers with hosts like\n`x.example.com` as well as `example.com` where the first host is a subdomain\nof the second host.\n\n(The HSTS cache either needs to have been populated manually or there needs to\nhave been previous HTTPS accesses done as the cache needs to have entries for\nthe domains involved to trigger this problem.)\n\nWhen `x.example.com` responds with `Strict-Transport-Security:` headers, this\nbug can make the subdomain's expiry timeout *bleed over* and get set for the\nparent domain `example.com` in curl's HSTS cache.\n\nThe result of a triggered bug is that HTTP accesses to `example.com` get\nconverted to HTTPS for a different period of time than what was asked for by\nthe origin server. If `example.com` for example stops supporting HTTPS at its\nexpiry time, curl might then fail to access `http://example.com` until the\n(wrongly set) timeout expires. This bug can also expire the parent's entry\n*earlier*, thus making curl inadvertently switch back to insecure HTTP earlier\nthan otherwise intended."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-9681","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-9681","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9681","cwe":"CWE-697","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-9681","date":"2026-10-08","epss":0.01987,"percentile":0.79983}],"risk":0.6855149999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-9681","description":"A vulnerability was found in curl. When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than intended."},"relatedVulnerabilities":[{"id":"CVE-2024-9681","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9681","cwe":"CWE-697","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-9681","date":"2026-10-08","epss":0.01987,"percentile":0.79983}],"urls":["https://curl.se/docs/CVE-2024-9681.html","https://curl.se/docs/CVE-2024-9681.json","https://hackerone.com/reports/2764830","http://seclists.org/fulldisclosure/2025/Apr/10","http://seclists.org/fulldisclosure/2025/Apr/11","http://seclists.org/fulldisclosure/2025/Apr/12","http://seclists.org/fulldisclosure/2025/Apr/13","http://seclists.org/fulldisclosure/2025/Apr/4","http://seclists.org/fulldisclosure/2025/Apr/5","http://seclists.org/fulldisclosure/2025/Apr/8","http://seclists.org/fulldisclosure/2025/Apr/9","http://www.openwall.com/lists/oss-security/2024/11/06/2","https://security.netapp.com/advisory/ntap-20241213-0006/","https://github.com/curl/curl/commit/7385610d0c74c6a25","https://github.com/curl/curl/commit/a94973805df96269bf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-9681","description":"When curl is asked to use HSTS, the expiry time for a subdomain might\noverwrite a parent domain's cache entry, making it end sooner or later than\notherwise intended.\n\nThis affects curl using applications that enable HSTS and use URLs with the\ninsecure `HTTP://` scheme and perform transfers with hosts like\n`x.example.com` as well as `example.com` where the first host is a subdomain\nof the second host.\n\n(The HSTS cache either needs to have been populated manually or there needs to\nhave been previous HTTPS accesses done as the cache needs to have entries for\nthe domains involved to trigger this problem.)\n\nWhen `x.example.com` responds with `Strict-Transport-Security:` headers, this\nbug can make the subdomain's expiry timeout *bleed over* and get set for the\nparent domain `example.com` in curl's HSTS cache.\n\nThe result of a triggered bug is that HTTP accesses to `example.com` get\nconverted to HTTPS for a different period of time than what was asked for by\nthe origin server. If `example.com` for example stops supporting HTTPS at its\nexpiry time, curl might then fail to access `http://example.com` until the\n(wrongly set) timeout expires. This bug can also expire the parent's entry\n*earlier*, thus making curl inadvertently switch back to insecure HTTP earlier\nthan otherwise intended."}]},{"artifact":{"id":"4987714346273301","cpes":["cpe:2.3:a:libssh:libssh:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh:0.10.4-19.el9_8:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:rpm/redhat/libssh@0.10.4-19.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libssh-0.10.4-19.el9_8.src.rpm","type":"rpm","version":"0.10.4-19.el9_8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3731","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libssh","version":"0:0.10.4-19.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-3731","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3731","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-3731","cwe":"CWE-125","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-3731","date":"2026-10-08","epss":0.012,"percentile":0.67273}],"risk":0.6180000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3731","description":"A flaw was found in libssh. A remote attacker could trigger an out-of-bounds read vulnerability in the SFTP Extension Name Handler by manipulating the `idx` argument in the `sftp_extensions_get_name` or `sftp_extensions_get_data` functions. This could lead to a Denial of Service (DoS), making the affected system unresponsive."},"relatedVulnerabilities":[{"id":"CVE-2026-3731","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3731","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-3731","cwe":"CWE-125","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-3731","date":"2026-10-08","epss":0.012,"percentile":0.67273}],"urls":["https://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60","https://vuldb.com/?ctiid.349709","https://vuldb.com/?id.349709","https://vuldb.com/?submit.767120","https://www.libssh.org/files/0.12/libssh-0.12.0.tar.xz","https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3731","description":"A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component."}]},{"artifact":{"id":"6b32f79bfc4dbf71","cpes":["cpe:2.3:a:libssh-config:libssh-config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:libssh-config:libssh_config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh-config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh_config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh-config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh_config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh-config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh_config:0.10.4-19.el9_8:*:*:*:*:*:*:*"],"name":"libssh-config","purl":"pkg:rpm/redhat/libssh-config@0.10.4-19.el9_8?arch=noarch&distro=rhel-9.8&upstream=libssh-0.10.4-19.el9_8.src.rpm","type":"rpm","version":"0.10.4-19.el9_8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh","version":"0.10.4-19.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3731","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libssh","version":"0.10.4-19.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-3731","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3731","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-3731","cwe":"CWE-125","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-3731","date":"2026-10-08","epss":0.012,"percentile":0.67273}],"risk":0.6180000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3731","description":"A flaw was found in libssh. A remote attacker could trigger an out-of-bounds read vulnerability in the SFTP Extension Name Handler by manipulating the `idx` argument in the `sftp_extensions_get_name` or `sftp_extensions_get_data` functions. This could lead to a Denial of Service (DoS), making the affected system unresponsive."},"relatedVulnerabilities":[{"id":"CVE-2026-3731","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3731","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-3731","cwe":"CWE-125","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-3731","date":"2026-10-08","epss":0.012,"percentile":0.67273}],"urls":["https://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60","https://vuldb.com/?ctiid.349709","https://vuldb.com/?id.349709","https://vuldb.com/?submit.767120","https://www.libssh.org/files/0.12/libssh-0.12.0.tar.xz","https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3731","description":"A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-9232","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-9232","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9232","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9232","date":"2026-10-08","epss":0.02001,"percentile":0.80128}],"risk":0.610305,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-9232","description":"A flaw was found in the OpenSSL HTTP client API no_proxy handling. This vulnerability allows an application level denial of service (application crash) via an attacker-controlled IPv6 URL when the no_proxy environment variable is set."},"relatedVulnerabilities":[{"id":"CVE-2025-9232","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9232","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9232","date":"2026-10-08","epss":0.02001,"percentile":0.80128}],"urls":["https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35","https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b","https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3","https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf","https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0","https://openssl-library.org/news/secadv/20250930.txt","http://www.openwall.com/lists/oss-security/2025/09/30/5","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9232","description":"Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-9232","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-9232","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9232","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9232","date":"2026-10-08","epss":0.02001,"percentile":0.80128}],"risk":0.610305,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-9232","description":"A flaw was found in the OpenSSL HTTP client API no_proxy handling. This vulnerability allows an application level denial of service (application crash) via an attacker-controlled IPv6 URL when the no_proxy environment variable is set."},"relatedVulnerabilities":[{"id":"CVE-2025-9232","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9232","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9232","date":"2026-10-08","epss":0.02001,"percentile":0.80128}],"urls":["https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35","https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b","https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3","https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf","https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0","https://openssl-library.org/news/secadv/20250930.txt","http://www.openwall.com/lists/oss-security/2025/09/30/5","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9232","description":"Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-9232","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-9232","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9232","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9232","date":"2026-10-08","epss":0.02001,"percentile":0.80128}],"risk":0.610305,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-9232","description":"A flaw was found in the OpenSSL HTTP client API no_proxy handling. This vulnerability allows an application level denial of service (application crash) via an attacker-controlled IPv6 URL when the no_proxy environment variable is set."},"relatedVulnerabilities":[{"id":"CVE-2025-9232","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9232","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9232","date":"2026-10-08","epss":0.02001,"percentile":0.80128}],"urls":["https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35","https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b","https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3","https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf","https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0","https://openssl-library.org/news/secadv/20250930.txt","http://www.openwall.com/lists/oss-security/2025/09/30/5","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9232","description":"Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-11053","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-11053","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-11053","date":"2026-10-08","epss":0.01348,"percentile":0.7063}],"risk":0.5998600000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-11053","description":"A flaw was found in curl. A logic error when processing credentials from the .netrc file while performing redirects allows the transfer of credentials from the original host to the followed-to host under certain circumstances, leaking the credentials to the followed-to host."},"relatedVulnerabilities":[{"id":"CVE-2024-11053","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":3.4,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-11053","date":"2026-10-08","epss":0.01348,"percentile":0.7063}],"urls":["https://curl.se/docs/CVE-2024-11053.html","https://curl.se/docs/CVE-2024-11053.json","https://hackerone.com/reports/2829063","http://www.openwall.com/lists/oss-security/2024/12/11/1","https://security.netapp.com/advisory/ntap-20250124-0012/","https://security.netapp.com/advisory/ntap-20250131-0003/","https://security.netapp.com/advisory/ntap-20250131-0004/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-11053","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-11053","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-11053","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-11053","date":"2026-10-08","epss":0.01348,"percentile":0.7063}],"risk":0.5998600000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-11053","description":"A flaw was found in curl. A logic error when processing credentials from the .netrc file while performing redirects allows the transfer of credentials from the original host to the followed-to host under certain circumstances, leaking the credentials to the followed-to host."},"relatedVulnerabilities":[{"id":"CVE-2024-11053","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":3.4,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-11053","date":"2026-10-08","epss":0.01348,"percentile":0.7063}],"urls":["https://curl.se/docs/CVE-2024-11053.html","https://curl.se/docs/CVE-2024-11053.json","https://hackerone.com/reports/2829063","http://www.openwall.com/lists/oss-security/2024/12/11/1","https://security.netapp.com/advisory/ntap-20250124-0012/","https://security.netapp.com/advisory/ntap-20250131-0003/","https://security.netapp.com/advisory/ntap-20250131-0004/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-11053","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password."}]},{"artifact":{"id":"8cf05c8343d9a4a8","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.5.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0990","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0990","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0990","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0990","date":"2026-10-08","epss":0.00969,"percentile":0.60707}],"risk":0.528105,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0990","description":"A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications."},"relatedVulnerabilities":[{"id":"CVE-2026-0990","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0990","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0990","date":"2026-10-08","epss":0.00969,"percentile":0.60707}],"urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-0990","https://bugzilla.redhat.com/show_bug.cgi?id=2429959","https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0990","description":"A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-41996","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-41996","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41996","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-41996","date":"2026-10-08","epss":0.01083,"percentile":0.6416}],"risk":0.481935,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-41996","description":"A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server's public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations."},"relatedVulnerabilities":[{"id":"CVE-2024-41996","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41996","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-41996","date":"2026-10-08","epss":0.01083,"percentile":0.6416}],"urls":["https://dheatattack.gitlab.io/details/","https://dheatattack.gitlab.io/faq/","https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41996","description":"Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-41996","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-41996","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41996","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-41996","date":"2026-10-08","epss":0.01083,"percentile":0.6416}],"risk":0.481935,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-41996","description":"A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server's public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations."},"relatedVulnerabilities":[{"id":"CVE-2024-41996","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41996","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-41996","date":"2026-10-08","epss":0.01083,"percentile":0.6416}],"urls":["https://dheatattack.gitlab.io/details/","https://dheatattack.gitlab.io/faq/","https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41996","description":"Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-41996","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-41996","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41996","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-41996","date":"2026-10-08","epss":0.01083,"percentile":0.6416}],"risk":0.481935,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-41996","description":"A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server's public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations."},"relatedVulnerabilities":[{"id":"CVE-2024-41996","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41996","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-41996","date":"2026-10-08","epss":0.01083,"percentile":0.6416}],"urls":["https://dheatattack.gitlab.io/details/","https://dheatattack.gitlab.io/faq/","https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41996","description":"Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-41409","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-41409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41409","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41409","date":"2026-10-08","epss":0.01121,"percentile":0.65174}],"risk":0.465215,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-41409","description":"A flaw was found in PCRE2, where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack."},"relatedVulnerabilities":[{"id":"CVE-2022-41409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41409","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41409","date":"2026-10-08","epss":0.01121,"percentile":0.65174}],"urls":["https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35","https://github.com/PCRE2Project/pcre2/issues/141"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41409","description":"Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-41409","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-41409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41409","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41409","date":"2026-10-08","epss":0.01121,"percentile":0.65174}],"risk":0.465215,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-41409","description":"A flaw was found in PCRE2, where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack."},"relatedVulnerabilities":[{"id":"CVE-2022-41409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41409","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41409","date":"2026-10-08","epss":0.01121,"percentile":0.65174}],"urls":["https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35","https://github.com/PCRE2Project/pcre2/issues/141"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41409","description":"Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input."}]},{"artifact":{"id":"7ea496b1a090c4af","cpes":["cpe:2.3:a:ncurses:ncurses:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses:6.2-12.20210508.el9:*:*:*:*:*:*:*"],"name":"ncurses","purl":"pkg:rpm/redhat/ncurses@6.2-12.20210508.el9?arch=x86_64&distro=rhel-9.8&upstream=ncurses-6.2-12.20210508.el9.src.rpm","type":"rpm","version":"6.2-12.20210508.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"ncurses","version":"0:6.2-12.20210508.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.45315,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-50495","description":"A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"ecae56e691f56928","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-base:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_base:6.2-12.20210508.el9:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:rpm/redhat/ncurses-base@6.2-12.20210508.el9?arch=noarch&distro=rhel-9.8&upstream=ncurses-6.2-12.20210508.el9.src.rpm","type":"rpm","version":"6.2-12.20210508.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.2-12.20210508.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"ncurses","version":"6.2-12.20210508.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.45315,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-50495","description":"A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"b0fd3764b473721b","cpes":["cpe:2.3:a:ncurses-libs:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-libs:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-libs:6.2-12.20210508.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_libs:6.2-12.20210508.el9:*:*:*:*:*:*:*"],"name":"ncurses-libs","purl":"pkg:rpm/redhat/ncurses-libs@6.2-12.20210508.el9?arch=x86_64&distro=rhel-9.8&upstream=ncurses-6.2-12.20210508.el9.src.rpm","type":"rpm","version":"6.2-12.20210508.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.2-12.20210508.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"ncurses","version":"6.2-12.20210508.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.45315,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-50495","description":"A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.430965,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77214","description":"A flaw was found in expat. A remote attacker can exploit this vulnerability through repeated parse buffer operations with unvalidated buffer lengths, causing a heap buffer over-read. This issue primarily leads to information disclosure by leaking adjacent heap memory contents, which could assist in bypassing security mitigations such as Address Space Layout Randomization (ASLR), or result in a Denial of Service (DoS) by crashing the application."},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.42952499999999993,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19931","description":"A flaw was found in libcurl. This vulnerability allows an attacker to reuse an HTTP connection set up for a given hostname using Negotiate authentication. When an initial request is made with empty credentials, a subsequent user's request can be sent over a previously authenticated connection belonging to another user. This could lead to information disclosure or unauthorized access to sensitive data."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.42952499999999993,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19931","description":"A flaw was found in libcurl. This vulnerability allows an attacker to reuse an HTTP connection set up for a given hostname using Negotiate authentication. When an initial request is made with empty credentials, a subsequent user's request can be sent over a previously authenticated connection belonging to another user. This could lead to information disclosure or unauthorized access to sensitive data."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"8cf05c8343d9a4a8","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.5.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-45322","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-45322","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45322","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45322","date":"2026-10-08","epss":0.00965,"percentile":0.60527}],"risk":0.4294250000000001,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-45322","description":"A flaw was found in libxml2. In an out-of-memory condition or when limiting the memory allocation, processing a XML document using the HTML parser may result in a use-after-free vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2023-45322","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45322","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45322","date":"2026-10-08","epss":0.00965,"percentile":0.60527}],"urls":["http://www.openwall.com/lists/oss-security/2023/10/06/5","https://gitlab.gnome.org/GNOME/libxml2/-/issues/344","https://gitlab.gnome.org/GNOME/libxml2/-/issues/583","https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45322","description":"libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is \"I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail.\""}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.39559999999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11856","description":"A flaw was found in curl. When `libcurl` performs a transfer to an HTTP origin using Digest authentication and then reuses the same connection handle for a subsequent transfer to a different origin, it may incorrectly send the authentication header intended for the first origin to the second. This could lead to unintended information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.39559999999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11856","description":"A flaw was found in curl. When `libcurl` performs a transfer to an HTTP origin using Digest authentication and then reuses the same connection handle for a subsequent transfer to a different origin, it may incorrectly send the authentication header intended for the first origin to the second. This could lead to unintended information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.38625,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6253","description":"A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy's credentials. This improper credential management (CWE-522) may allow an attacker to gain unauthorized access or information by intercepting these disclosed credentials."},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.38625,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6253","description":"A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy's credentials. This improper credential management (CWE-522) may allow an attacker to gain unauthorized access or information by intercepting these disclosed credentials."},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"313fc89a99c1b307","cpes":["cpe:2.3:a:libatomic:libatomic:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libatomic:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libatomic","purl":"pkg:rpm/redhat/libatomic@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-27943","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"risk":0.38505000000000006,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-27943","description":"A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2022-27943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."}]},{"artifact":{"id":"23e3d9feac1cb13c","cpes":["cpe:2.3:a:libgcc:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-27943","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"risk":0.38505000000000006,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-27943","description":"A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2022-27943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."}]},{"artifact":{"id":"62a2970ccab3dd86","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-27943","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"risk":0.38505000000000006,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-27943","description":"A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2022-27943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.380075,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8924","description":"A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.380075,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8924","description":"A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5773","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-5773","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"risk":0.37777499999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5773","description":"A flaw was found in libcurl. Due to a logical error in the connection reuse mechanism for SMB (Server Message Block) transfers, libcurl might reuse an existing SMB connection with a different share than intended. This vulnerability, categorized as CWE-488 (Exposure of Data Element to Wrong Session), could lead to the download of an incorrect file or the upload of a file to an unintended location when an application uses libcurl for SMB transfers."},"relatedVulnerabilities":[{"id":"CVE-2026-5773","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"urls":["https://curl.se/docs/CVE-2026-5773.html","https://curl.se/docs/CVE-2026-5773.json","https://hackerone.com/reports/3650689","http://www.openwall.com/lists/oss-security/2026/04/29/9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5773","description":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5773","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-5773","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"risk":0.37777499999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5773","description":"A flaw was found in libcurl. Due to a logical error in the connection reuse mechanism for SMB (Server Message Block) transfers, libcurl might reuse an existing SMB connection with a different share than intended. This vulnerability, categorized as CWE-488 (Exposure of Data Element to Wrong Session), could lead to the download of an incorrect file or the upload of a file to an unintended location when an application uses libcurl for SMB transfers."},"relatedVulnerabilities":[{"id":"CVE-2026-5773","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"urls":["https://curl.se/docs/CVE-2026-5773.html","https://curl.se/docs/CVE-2026-5773.json","https://hackerone.com/reports/3650689","http://www.openwall.com/lists/oss-security/2026/04/29/9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5773","description":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same."}]},{"artifact":{"id":"6b29b8ef2f83cc22","cpes":["cpe:2.3:a:redhat:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm","purl":"pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-95521","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"0:4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95521","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"risk":0.37184,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."},"relatedVulnerabilities":[{"id":"CVE-2026-95521","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"urls":["https://access.redhat.com/security/cve/CVE-2026-95521","https://bugzilla.redhat.com/show_bug.cgi?id=2537812"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."}]},{"artifact":{"id":"108e4bcd5f0cf305","cpes":["cpe:2.3:a:rpm-libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm-libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm-libs","purl":"pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.16.1.3-40.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95521","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95521","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"risk":0.37184,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."},"relatedVulnerabilities":[{"id":"CVE-2026-95521","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"urls":["https://access.redhat.com/security/cve/CVE-2026-95521","https://bugzilla.redhat.com/show_bug.cgi?id=2537812"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-32636","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-32636","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-32636","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-32636","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-32636","date":"2026-10-08","epss":0.00774,"percentile":0.54361}],"risk":0.35604,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-32636","description":"A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499."},"relatedVulnerabilities":[{"id":"CVE-2023-32636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-32636","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-32636","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-32636","date":"2026-10-08","epss":0.00774,"percentile":0.54361}],"urls":["https://gitlab.gnome.org/GNOME/glib/-/issues/2841","https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835","https://security.netapp.com/advisory/ntap-20231110-0002/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-32636","description":"A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499."}]},{"artifact":{"id":"987c8daac6c0f9f4","cpes":["cpe:2.3:a:libsolv:libsolv:0.7.24-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libsolv:0.7.24-6.el9_8:*:*:*:*:*:*:*"],"name":"libsolv","purl":"pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libsolv-0.7.24-6.el9_8.src.rpm","type":"rpm","version":"0.7.24-6.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9150","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libsolv","version":"0:0.7.24-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-9150","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9150","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-9150","date":"2026-10-08","epss":0.00581,"percentile":0.4607}],"risk":0.334075,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-9150","description":"A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-9150","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9150","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-9150","date":"2026-10-08","epss":0.00581,"percentile":0.4607}],"urls":["https://access.redhat.com/errata/RHSA-2026:21333","https://access.redhat.com/errata/RHSA-2026:28236","https://access.redhat.com/errata/RHSA-2026:30649","https://access.redhat.com/errata/RHSA-2026:48818","https://access.redhat.com/security/cve/CVE-2026-9150","https://bugzilla.redhat.com/show_bug.cgi?id=2460379","https://github.com/openSUSE/libsolv/pull/616"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9150","description":"A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system."}]},{"artifact":{"id":"e988ae274c693810","cpes":["cpe:2.3:a:redhat:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=tar-1.34-13.el9_8.src.rpm","type":"rpm","version":"2:1.34-13.el9_8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59871","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"tar","version":"2:1.34-13.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-59871","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59871","cwe":"CWE-704","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59871","date":"2026-10-08","epss":0.00644,"percentile":0.4927}],"risk":0.33166,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-59871","description":"A flaw was found in node-tar, a library for manipulating tar archives in Node.js. This vulnerability occurs when the library incorrectly converts specific archive path values into numbers, leading to an error during subsequent path processing. An attacker could exploit this to cause the application using node-tar to crash, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-59871","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59871","cwe":"CWE-704","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59871","date":"2026-10-08","epss":0.00644,"percentile":0.4927}],"urls":["https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b","https://github.com/isaacs/node-tar/releases/tag/v7.5.18","https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59871","description":"node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18."}]},{"artifact":{"id":"987c8daac6c0f9f4","cpes":["cpe:2.3:a:libsolv:libsolv:0.7.24-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libsolv:0.7.24-6.el9_8:*:*:*:*:*:*:*"],"name":"libsolv","purl":"pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libsolv-0.7.24-6.el9_8.src.rpm","type":"rpm","version":"0.7.24-6.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9149","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libsolv","version":"0:0.7.24-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-9149","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9149","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-9149","date":"2026-10-08","epss":0.00568,"percentile":0.45338}],"risk":0.3266,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-9149","description":"A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-9149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9149","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-9149","date":"2026-10-08","epss":0.00568,"percentile":0.45338}],"urls":["https://access.redhat.com/errata/RHSA-2026:21333","https://access.redhat.com/errata/RHSA-2026:28236","https://access.redhat.com/errata/RHSA-2026:48818","https://access.redhat.com/security/cve/CVE-2026-9149","https://bugzilla.redhat.com/show_bug.cgi?id=2460380","https://github.com/openSUSE/libsolv/pull/617"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9149","description":"A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS)."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14524","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-14524","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-08","epss":0.0068,"percentile":0.50927}],"risk":0.32299999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-14524","description":"A flaw was found in curl. When an OAuth2 (Open Authorization) bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a different scheme like IMAP, LDAP, POP3, or SMTP, curl might incorrectly pass the bearer token to the new target host. This could lead to information disclosure, where sensitive authentication tokens are exposed to unintended recipients."},"relatedVulnerabilities":[{"id":"CVE-2025-14524","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-08","epss":0.0068,"percentile":0.50927}],"urls":["https://curl.se/docs/CVE-2025-14524.html","https://curl.se/docs/CVE-2025-14524.json","https://hackerone.com/reports/3459417","http://www.openwall.com/lists/oss-security/2026/01/07/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14524","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14524","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-14524","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-08","epss":0.0068,"percentile":0.50927}],"risk":0.32299999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-14524","description":"A flaw was found in curl. When an OAuth2 (Open Authorization) bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a different scheme like IMAP, LDAP, POP3, or SMTP, curl might incorrectly pass the bearer token to the new target host. This could lead to information disclosure, where sensitive authentication tokens are exposed to unintended recipients."},"relatedVulnerabilities":[{"id":"CVE-2025-14524","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-08","epss":0.0068,"percentile":0.50927}],"urls":["https://curl.se/docs/CVE-2025-14524.html","https://curl.se/docs/CVE-2025-14524.json","https://hackerone.com/reports/3459417","http://www.openwall.com/lists/oss-security/2026/01/07/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14524","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host."}]},{"artifact":{"id":"e1b413eca8446714","cpes":["cpe:2.3:a:libarchive:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libarchive-3.5.3-11.el9_8.src.rpm","type":"rpm","version":"3.5.3-11.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4426","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libarchive","version":"0:3.5.3-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4426","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4426","cwe":"CWE-1335","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4426","date":"2026-10-08","epss":0.0056,"percentile":0.44879}],"risk":0.32199999999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4426","description":"A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition."},"relatedVulnerabilities":[{"id":"CVE-2026-4426","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4426","cwe":"CWE-1335","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4426","date":"2026-10-08","epss":0.0056,"percentile":0.44879}],"urls":["https://access.redhat.com/errata/RHSA-2026:8944","https://access.redhat.com/security/cve/CVE-2026-4426","https://bugzilla.redhat.com/show_bug.cgi?id=2449010","https://github.com/libarchive/libarchive/pull/2897"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4426","description":"A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition."}]},{"artifact":{"id":"8cf05c8343d9a4a8","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.5.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-27113","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-27113","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-27113","date":"2026-10-08","epss":0.01053,"percentile":0.63313}],"risk":0.321165,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-27113","description":"A flaw was found in libxml2. This vulnerability allows a NULL pointer dereference, leading to a potential crash or denial of service via a crafted XML pattern."},"relatedVulnerabilities":[{"id":"CVE-2025-27113","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-27113","date":"2026-10-08","epss":0.01053,"percentile":0.63313}],"urls":["https://gitlab.gnome.org/GNOME/libxml2/-/issues/861","http://seclists.org/fulldisclosure/2025/Apr/10","http://seclists.org/fulldisclosure/2025/Apr/11","http://seclists.org/fulldisclosure/2025/Apr/12","http://seclists.org/fulldisclosure/2025/Apr/13","http://seclists.org/fulldisclosure/2025/Apr/4","http://seclists.org/fulldisclosure/2025/Apr/5","http://seclists.org/fulldisclosure/2025/Apr/8","http://seclists.org/fulldisclosure/2025/Apr/9","https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html","https://security.netapp.com/advisory/ntap-20250306-0004/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-27113","description":"libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-28387","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28387","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"risk":0.31590499999999994,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28387","description":"A flaw was found in OpenSSL. An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. This vulnerability could lead to data corruption, application crashes, or, in severe cases, arbitrary code execution. This issue is highly specific and uncommon, as it only affects clients using both PKIX-TA(0)/PKIX-EE(1) and DANE-TA(2) certificate usages and communicating with a server publishing a TLSA record set with both types of records."},"relatedVulnerabilities":[{"id":"CVE-2026-28387","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"urls":["https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b","https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe","https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3","https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7","https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28387","description":"Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28387","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28387","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"risk":0.31590499999999994,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28387","description":"A flaw was found in OpenSSL. An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. This vulnerability could lead to data corruption, application crashes, or, in severe cases, arbitrary code execution. This issue is highly specific and uncommon, as it only affects clients using both PKIX-TA(0)/PKIX-EE(1) and DANE-TA(2) certificate usages and communicating with a server publishing a TLSA record set with both types of records."},"relatedVulnerabilities":[{"id":"CVE-2026-28387","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"urls":["https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b","https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe","https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3","https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7","https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28387","description":"Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28387","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-28387","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"risk":0.31590499999999994,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28387","description":"A flaw was found in OpenSSL. An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. This vulnerability could lead to data corruption, application crashes, or, in severe cases, arbitrary code execution. This issue is highly specific and uncommon, as it only affects clients using both PKIX-TA(0)/PKIX-EE(1) and DANE-TA(2) certificate usages and communicating with a server publishing a TLSA record set with both types of records."},"relatedVulnerabilities":[{"id":"CVE-2026-28387","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"urls":["https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b","https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe","https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3","https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7","https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28387","description":"Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.30928999999999995,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86145","description":"A flaw was found in PCRE2. An out-of-bounds write vulnerability exists in the `pcre2_dfa_match` function due to improper size checking when reusing cached workspace blocks. A remote attacker could exploit this by providing a specially crafted regular expression or a recursive pattern in conjunction with a small heap limit. This could lead to data corruption or potentially arbitrary code execution, compromising the integrity and availability of the system."},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.30928999999999995,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86145","description":"A flaw was found in PCRE2. An out-of-bounds write vulnerability exists in the `pcre2_dfa_match` function due to improper size checking when reusing cached workspace blocks. A remote attacker could exploit this by providing a specially crafted regular expression or a recursive pattern in conjunction with a small heap limit. This could lead to data corruption or potentially arbitrary code execution, compromising the integrity and availability of the system."},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-15079","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"risk":0.30524999999999997,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15079","description":"A flaw was found in curl. When performing SSH-based transfers using SCP or SFTP, libcurl could mistakenly connect to hosts not listed in the user-specified knownhosts file. This occurs if the host is present in the libssh global knownhosts file, effectively bypassing the intended host verification. This could allow a remote attacker to connect to an untrusted host, potentially leading to information disclosure or man-in-the-middle attacks."},"relatedVulnerabilities":[{"id":"CVE-2025-15079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-15079","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"risk":0.30524999999999997,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15079","description":"A flaw was found in curl. When performing SSH-based transfers using SCP or SFTP, libcurl could mistakenly connect to hosts not listed in the user-specified knownhosts file. This occurs if the host is present in the libssh global knownhosts file, effectively bypassing the intended host verification. This could allow a remote attacker to connect to an untrusted host, potentially leading to information disclosure or man-in-the-middle attacks."},"relatedVulnerabilities":[{"id":"CVE-2025-15079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7168","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-7168","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-08","epss":0.00591,"percentile":0.46599}],"risk":0.304365,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7168","description":"A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authentication and then reuses the same handle for a second transfer with a different proxy host, libcurl incorrectly sends the `Proxy-Authorization` header intended for the first proxy to the second proxy. This could lead to the disclosure of sensitive authentication information to an unintended proxy, potentially allowing an attacker to gain unauthorized access or impersonate the user."},"relatedVulnerabilities":[{"id":"CVE-2026-7168","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-08","epss":0.00591,"percentile":0.46599}],"urls":["https://curl.se/docs/CVE-2026-7168.html","https://curl.se/docs/CVE-2026-7168.json","https://hackerone.com/reports/3697719","http://www.openwall.com/lists/oss-security/2026/04/29/14"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7168","description":"Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7168","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-7168","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-08","epss":0.00591,"percentile":0.46599}],"risk":0.304365,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7168","description":"A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authentication and then reuses the same handle for a second transfer with a different proxy host, libcurl incorrectly sends the `Proxy-Authorization` header intended for the first proxy to the second proxy. This could lead to the disclosure of sensitive authentication information to an unintended proxy, potentially allowing an attacker to gain unauthorized access or impersonate the user."},"relatedVulnerabilities":[{"id":"CVE-2026-7168","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-08","epss":0.00591,"percentile":0.46599}],"urls":["https://curl.se/docs/CVE-2026-7168.html","https://curl.se/docs/CVE-2026-7168.json","https://hackerone.com/reports/3697719","http://www.openwall.com/lists/oss-security/2026/04/29/14"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7168","description":"Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`."}]},{"artifact":{"id":"f3e667a0375f3959","cpes":["cpe:2.3:a:xz-libs:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:xz-libs:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:xz_libs:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:xz_libs:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:xz:xz-libs:5.2.5-8.el9_0:*:*:*:*:*:*:*","cpe:2.3:a:xz:xz_libs:5.2.5-8.el9_0:*:*:*:*:*:*:*"],"name":"xz-libs","purl":"pkg:rpm/redhat/xz-libs@5.2.5-8.el9_0?arch=x86_64&distro=rhel-9.8&upstream=xz-5.2.5-8.el9_0.src.rpm","type":"rpm","version":"5.2.5-8.el9_0","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"xz","version":"5.2.5-8.el9_0"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34743","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"xz","version":"5.2.5-8.el9_0"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-34743","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-08","epss":0.00573,"percentile":0.45591}],"risk":0.295095,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-34743","description":"A flaw was found in XZ Utils. When the `lzma_index_decoder()` function processes an empty index, and a subsequent `lzma_index_append()` operation is performed, insufficient memory is allocated. This can lead to a buffer overflow, potentially causing a denial of service (DoS) for affected systems."},"relatedVulnerabilities":[{"id":"CVE-2026-34743","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-08","epss":0.00573,"percentile":0.45591}],"urls":["https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87","https://github.com/tukaani-project/xz/releases/tag/v5.8.3","https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv","http://www.openwall.com/lists/oss-security/2026/03/31/13","https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34743","description":"XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.2944,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6429","description":"A flaw was found in libcurl. When configured to use a .netrc file for credentials and follow HTTP redirects, libcurl can inadvertently send the password from the initial connection to the redirected host. This sensitive information disclosure occurs when both the original and redirect URLs use clear text HTTP, are performed over the same HTTP proxy, and the same connection is reused. This vulnerability, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), could allow an attacker to obtain user credentials."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.2944,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6429","description":"A flaw was found in libcurl. When configured to use a .netrc file for credentials and follow HTTP redirects, libcurl can inadvertently send the password from the initial connection to the redirected host. This sensitive information disclosure occurs when both the original and redirect URLs use clear text HTTP, are performed over the same HTTP proxy, and the same connection is reused. This vulnerability, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), could allow an attacker to obtain user credentials."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5545","description":"A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5545","description":"A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-2.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 1:3.5.8-2.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["1:3.5.8-2.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"1:3.5.8-2.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.29055,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:77396","link":"https://access.redhat.com/errata/RHSA-2026:77396"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84782","description":"A flaw was found in OpenSSL. The Datagram Transport Layer Security (DTLS) retransmission mechanism fails to properly handle handshake message writes that are suspended before completion. A remote attacker could exploit this vulnerability during handshake message retransmission, causing OpenSSL to read past the message buffer or overwrite internal state required to resume writing. This issue can result in information disclosure through out-of-bounds memory reads or cause a Denial of Service (DoS) by crashing the process."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-2.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 1:3.5.8-2.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["1:3.5.8-2.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"1:3.5.8-2.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.29055,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:77396","link":"https://access.redhat.com/errata/RHSA-2026:77396"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84782","description":"A flaw was found in OpenSSL. The Datagram Transport Layer Security (DTLS) retransmission mechanism fails to properly handle handshake message writes that are suspended before completion. A remote attacker could exploit this vulnerability during handshake message retransmission, causing OpenSSL to read past the message buffer or overwrite internal state required to resume writing. This issue can result in information disclosure through out-of-bounds memory reads or cause a Denial of Service (DoS) by crashing the process."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:3.5.8-2.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 1:3.5.8-2.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["1:3.5.8-2.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"1:3.5.8-2.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.29055,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:77396","link":"https://access.redhat.com/errata/RHSA-2026:77396"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84782","description":"A flaw was found in OpenSSL. The Datagram Transport Layer Security (DTLS) retransmission mechanism fails to properly handle handshake message writes that are suspended before completion. A remote attacker could exploit this vulnerability during handshake message retransmission, causing OpenSSL to read past the message buffer or overwrite internal state required to resume writing. This issue can result in information disclosure through out-of-bounds memory reads or cause a Denial of Service (DoS) by crashing the process."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"bb911813b45585f3","cpes":["cpe:2.3:a:perl-AutoLoader:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-AutoLoader:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_AutoLoader:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_AutoLoader:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-AutoLoader","purl":"pkg:rpm/redhat/perl-AutoLoader@5.74-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:5.74-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"7e60fe54e6c09824","cpes":["cpe:2.3:a:perl-B:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-B:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_B:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_B:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-B","purl":"pkg:rpm/redhat/perl-B@1.80-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.80-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"006f5e08bfc4c952","cpes":["cpe:2.3:a:perl-Class-Struct:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class-Struct:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class_Struct:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class_Struct:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Class-Struct","purl":"pkg:rpm/redhat/perl-Class-Struct@0.66-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.66-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"2a9a518a53c7512b","cpes":["cpe:2.3:a:perl-Errno:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Errno:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Errno:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Errno:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Errno","purl":"pkg:rpm/redhat/perl-Errno@1.30-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.30-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"f01ef4b3b3b90538","cpes":["cpe:2.3:a:perl-Fcntl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Fcntl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Fcntl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Fcntl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Fcntl","purl":"pkg:rpm/redhat/perl-Fcntl@1.13-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.13-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"965edf03abd14e95","cpes":["cpe:2.3:a:perl-File-Basename:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File-Basename:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_Basename:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_Basename:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-File-Basename","purl":"pkg:rpm/redhat/perl-File-Basename@2.85-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.85-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"7cb125d521892030","cpes":["cpe:2.3:a:perl-File-stat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File-stat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_stat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_stat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-File-stat","purl":"pkg:rpm/redhat/perl-File-stat@1.09-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.09-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"67e8889d83c474fb","cpes":["cpe:2.3:a:perl-FileHandle:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-FileHandle:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_FileHandle:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_FileHandle:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-FileHandle","purl":"pkg:rpm/redhat/perl-FileHandle@2.03-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.03-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"955cb53aefe39959","cpes":["cpe:2.3:a:perl-Getopt-Std:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt-Std:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt_Std:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt_Std:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Getopt-Std","purl":"pkg:rpm/redhat/perl-Getopt-Std@1.12-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.12-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"e824797a395c58fc","cpes":["cpe:2.3:a:perl-IO:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IO:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IO:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IO:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-IO","purl":"pkg:rpm/redhat/perl-IO@1.43-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.43-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"42816d98549babcf","cpes":["cpe:2.3:a:perl-IPC-Open3:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC-Open3:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC_Open3:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC_Open3:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-IPC-Open3","purl":"pkg:rpm/redhat/perl-IPC-Open3@1.21-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.21-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"7db8a261840c5baa","cpes":["cpe:2.3:a:perl-NDBM-File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM-File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM-File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-NDBM_File","purl":"pkg:rpm/redhat/perl-NDBM_File@1.15-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.15-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"4d811d3afb2547c9","cpes":["cpe:2.3:a:perl-POSIX:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-POSIX:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_POSIX:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_POSIX:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-POSIX","purl":"pkg:rpm/redhat/perl-POSIX@1.94-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.94-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"1bc88a0c5a9ab30a","cpes":["cpe:2.3:a:perl-SelectSaver:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-SelectSaver:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_SelectSaver:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_SelectSaver:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-SelectSaver","purl":"pkg:rpm/redhat/perl-SelectSaver@1.02-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.02-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"449e2b4e3fa8b962","cpes":["cpe:2.3:a:perl-Symbol:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Symbol:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Symbol:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Symbol:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Symbol","purl":"pkg:rpm/redhat/perl-Symbol@1.08-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.08-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"21c1a8a82e4461bf","cpes":["cpe:2.3:a:perl-base:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:rpm/redhat/perl-base@2.27-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.27-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"a0ae61863ea1a76d","cpes":["cpe:2.3:a:perl-if:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-if:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_if:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_if:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-if","purl":"pkg:rpm/redhat/perl-if@0.60.800-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.60.800-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"4ac7ee895d3c99ec","cpes":["cpe:2.3:a:perl-interpreter:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-interpreter:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_interpreter:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_interpreter:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-interpreter","purl":"pkg:rpm/redhat/perl-interpreter@5.32.1-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=4&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"4:5.32.1-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":4,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"bf2c1b6ec909c416","cpes":["cpe:2.3:a:perl-libs:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-libs:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_libs:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_libs:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-libs","purl":"pkg:rpm/redhat/perl-libs@5.32.1-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=4&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"4:5.32.1-484.el9_8","language":"","licenses":["(GPL+ or Artistic) and BSD and HSRL and MIT and UCD and Public domain"],"metadata":{"epoch":4,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"8deef1192afd481d","cpes":["cpe:2.3:a:perl-mro:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-mro:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_mro:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_mro:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-mro","purl":"pkg:rpm/redhat/perl-mro@1.23-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.23-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"9b9db6c4ad38ca1b","cpes":["cpe:2.3:a:perl-overload:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-overload:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overload:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overload:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-overload","purl":"pkg:rpm/redhat/perl-overload@1.31-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.31-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"e12188ce897a6a75","cpes":["cpe:2.3:a:perl-overloading:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-overloading:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overloading:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overloading:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-overloading","purl":"pkg:rpm/redhat/perl-overloading@0.02-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.02-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"103e8134631ed773","cpes":["cpe:2.3:a:perl-subs:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-subs:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_subs:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_subs:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-subs","purl":"pkg:rpm/redhat/perl-subs@1.03-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.03-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"7a082b0e6a9156ba","cpes":["cpe:2.3:a:perl-vars:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-vars:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_vars:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_vars:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-vars","purl":"pkg:rpm/redhat/perl-vars@1.05-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.05-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6659","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6659","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"risk":0.28193999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6659","description":"A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in `rand` function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-6659","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6659","cwe":"CWE-338","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-6659","date":"2026-10-08","epss":0.00508,"percentile":0.41527}],"urls":["https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e.patch","https://github.com/ronsavage/Crypt-PasswdMD5/pull/3","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm#L35-47","https://metacpan.org/release/RSAVAGE/Crypt-PasswdMD5-1.43/changes","http://www.openwall.com/lists/oss-security/2026/05/08/17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6659","description":"Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts.\n\nThe built-in rand function is predictable, and unsuitable for cryptography."}]},{"artifact":{"id":"bb911813b45585f3","cpes":["cpe:2.3:a:perl-AutoLoader:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-AutoLoader:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_AutoLoader:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_AutoLoader:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-AutoLoader","purl":"pkg:rpm/redhat/perl-AutoLoader@5.74-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:5.74-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"7e60fe54e6c09824","cpes":["cpe:2.3:a:perl-B:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-B:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_B:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_B:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-B","purl":"pkg:rpm/redhat/perl-B@1.80-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.80-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"006f5e08bfc4c952","cpes":["cpe:2.3:a:perl-Class-Struct:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class-Struct:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class_Struct:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class_Struct:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Class-Struct","purl":"pkg:rpm/redhat/perl-Class-Struct@0.66-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.66-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"2a9a518a53c7512b","cpes":["cpe:2.3:a:perl-Errno:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Errno:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Errno:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Errno:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Errno","purl":"pkg:rpm/redhat/perl-Errno@1.30-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.30-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"f01ef4b3b3b90538","cpes":["cpe:2.3:a:perl-Fcntl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Fcntl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Fcntl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Fcntl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Fcntl","purl":"pkg:rpm/redhat/perl-Fcntl@1.13-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.13-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"965edf03abd14e95","cpes":["cpe:2.3:a:perl-File-Basename:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File-Basename:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_Basename:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_Basename:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-File-Basename","purl":"pkg:rpm/redhat/perl-File-Basename@2.85-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.85-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"7cb125d521892030","cpes":["cpe:2.3:a:perl-File-stat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File-stat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_stat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_stat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-File-stat","purl":"pkg:rpm/redhat/perl-File-stat@1.09-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.09-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"67e8889d83c474fb","cpes":["cpe:2.3:a:perl-FileHandle:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-FileHandle:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_FileHandle:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_FileHandle:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-FileHandle","purl":"pkg:rpm/redhat/perl-FileHandle@2.03-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.03-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"955cb53aefe39959","cpes":["cpe:2.3:a:perl-Getopt-Std:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt-Std:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt_Std:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt_Std:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Getopt-Std","purl":"pkg:rpm/redhat/perl-Getopt-Std@1.12-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.12-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"e824797a395c58fc","cpes":["cpe:2.3:a:perl-IO:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IO:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IO:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IO:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-IO","purl":"pkg:rpm/redhat/perl-IO@1.43-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.43-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"42816d98549babcf","cpes":["cpe:2.3:a:perl-IPC-Open3:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC-Open3:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC_Open3:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC_Open3:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-IPC-Open3","purl":"pkg:rpm/redhat/perl-IPC-Open3@1.21-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.21-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"7db8a261840c5baa","cpes":["cpe:2.3:a:perl-NDBM-File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM-File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM-File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-NDBM_File","purl":"pkg:rpm/redhat/perl-NDBM_File@1.15-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.15-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"4d811d3afb2547c9","cpes":["cpe:2.3:a:perl-POSIX:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-POSIX:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_POSIX:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_POSIX:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-POSIX","purl":"pkg:rpm/redhat/perl-POSIX@1.94-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.94-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"1bc88a0c5a9ab30a","cpes":["cpe:2.3:a:perl-SelectSaver:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-SelectSaver:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_SelectSaver:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_SelectSaver:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-SelectSaver","purl":"pkg:rpm/redhat/perl-SelectSaver@1.02-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.02-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"449e2b4e3fa8b962","cpes":["cpe:2.3:a:perl-Symbol:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Symbol:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Symbol:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Symbol:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Symbol","purl":"pkg:rpm/redhat/perl-Symbol@1.08-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.08-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"21c1a8a82e4461bf","cpes":["cpe:2.3:a:perl-base:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:rpm/redhat/perl-base@2.27-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.27-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"a0ae61863ea1a76d","cpes":["cpe:2.3:a:perl-if:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-if:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_if:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_if:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-if","purl":"pkg:rpm/redhat/perl-if@0.60.800-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.60.800-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"4ac7ee895d3c99ec","cpes":["cpe:2.3:a:perl-interpreter:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-interpreter:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_interpreter:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_interpreter:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-interpreter","purl":"pkg:rpm/redhat/perl-interpreter@5.32.1-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=4&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"4:5.32.1-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":4,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"bf2c1b6ec909c416","cpes":["cpe:2.3:a:perl-libs:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-libs:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_libs:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_libs:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-libs","purl":"pkg:rpm/redhat/perl-libs@5.32.1-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=4&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"4:5.32.1-484.el9_8","language":"","licenses":["(GPL+ or Artistic) and BSD and HSRL and MIT and UCD and Public domain"],"metadata":{"epoch":4,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"8deef1192afd481d","cpes":["cpe:2.3:a:perl-mro:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-mro:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_mro:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_mro:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-mro","purl":"pkg:rpm/redhat/perl-mro@1.23-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.23-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"9b9db6c4ad38ca1b","cpes":["cpe:2.3:a:perl-overload:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-overload:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overload:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overload:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-overload","purl":"pkg:rpm/redhat/perl-overload@1.31-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.31-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"e12188ce897a6a75","cpes":["cpe:2.3:a:perl-overloading:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-overloading:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overloading:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overloading:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-overloading","purl":"pkg:rpm/redhat/perl-overloading@0.02-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.02-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"103e8134631ed773","cpes":["cpe:2.3:a:perl-subs:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-subs:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_subs:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_subs:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-subs","purl":"pkg:rpm/redhat/perl-subs@1.03-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.03-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"7a082b0e6a9156ba","cpes":["cpe:2.3:a:perl-vars:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-vars:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_vars:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_vars:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-vars","purl":"pkg:rpm/redhat/perl-vars@1.05-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.05-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-45190","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"risk":0.27829999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45190","description":"A flaw was found in Net::CIDR::Lite, a Perl module for handling IP address ranges. This vulnerability allows a remote attacker to bypass IP Access Control Lists (ACLs) due to improper validation of IP address and CIDR (Classless Inter-Domain Routing) mask inputs. Specifically, inputs containing trailing newlines or non-ASCII digit characters are incorrectly processed, leading to a mismatch between the intended and actual IP addresses. This can cause functions like `find()` and `bin_find()` to incorrectly allow or deny access, compromising network security policies."},"relatedVulnerabilities":[{"id":"CVE-2026-45190","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45190","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-45190","date":"2026-10-08","epss":0.00484,"percentile":0.39737}],"urls":["https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692.patch","https://metacpan.org/release/STIGTSP/Net-CIDR-Lite-0.24/changes","https://www.cve.org/CVERecord?id=CVE-2026-45191"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45190","description":"Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.\n\nInputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled. find() and bin_find() can match or miss addresses as a result.\n\nExample:\n\n  my $cidr = Net::CIDR::Lite->new();\n  $cidr->add(\"::1\\n/128\");\n  $cidr->find(\"::1a\");  # incorrectly returns true\n\nSee also CVE-2026-45191."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3784","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-3784","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-08","epss":0.00469,"percentile":0.38615}],"risk":0.26967499999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3784","description":"A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy connection when performing a CONNECT request to a server, even if the new request uses different authentication credentials for the HTTP proxy. This improper connection reuse could lead to an attacker gaining unauthorized access to resources or information intended for a different user."},"relatedVulnerabilities":[{"id":"CVE-2026-3784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-08","epss":0.00469,"percentile":0.38615}],"urls":["https://curl.se/docs/CVE-2026-3784.html","https://curl.se/docs/CVE-2026-3784.json","https://hackerone.com/reports/3584903","http://www.openwall.com/lists/oss-security/2026/03/11/3","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3784","description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3784","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-3784","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-08","epss":0.00469,"percentile":0.38615}],"risk":0.26967499999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3784","description":"A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy connection when performing a CONNECT request to a server, even if the new request uses different authentication credentials for the HTTP proxy. This improper connection reuse could lead to an attacker gaining unauthorized access to resources or information intended for a different user."},"relatedVulnerabilities":[{"id":"CVE-2026-3784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-08","epss":0.00469,"percentile":0.38615}],"urls":["https://curl.se/docs/CVE-2026-3784.html","https://curl.se/docs/CVE-2026-3784.json","https://hackerone.com/reports/3584903","http://www.openwall.com/lists/oss-security/2026/03/11/3","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3784","description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76641","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-76641","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76641","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76641","date":"2026-10-08","epss":0.00353,"percentile":0.26927}],"risk":0.26475,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-76641","description":"A flaw was found in Expat. Attackers can exploit an out-of-bounds read vulnerability by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. This can lead to memory corruption. Specifically, a mismatch in struct sizes can cause a read past memory boundaries, potentially resulting in a denial of service (DoS) due to a segfault or incorrect handling of XML attributes."},"relatedVulnerabilities":[{"id":"CVE-2026-76641","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76641","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76641","date":"2026-10-08","epss":0.00353,"percentile":0.26927}],"urls":["https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf","https://github.com/libexpat/libexpat/pull/1331","https://www.vulncheck.com/advisories/expat-out-of-bounds-read-via-dtdcopy"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76641","description":"Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.264,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75804","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) due to missing connection-level flow control enforcement in the QUIC protocol implementation. By opening multiple streams that respect individual stream limits while preventing data consumption, the attacker can force the system to buffer far more data than permitted by the connection limit. This excessive memory allocation can exhaust available system resources and degrade or terminate the service."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.264,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75804","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) due to missing connection-level flow control enforcement in the QUIC protocol implementation. By opening multiple streams that respect individual stream limits while preventing data consumption, the attacker can force the system to buffer far more data than permitted by the connection limit. This excessive memory allocation can exhaust available system resources and degrade or terminate the service."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.264,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75804","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) due to missing connection-level flow control enforcement in the QUIC protocol implementation. By opening multiple streams that respect individual stream limits while preventing data consumption, the attacker can force the system to buffer far more data than permitted by the connection limit. This excessive memory allocation can exhaust available system resources and degrade or terminate the service."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e988ae274c693810","cpes":["cpe:2.3:a:redhat:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=tar-1.34-13.el9_8.src.rpm","type":"rpm","version":"2:1.34-13.el9_8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59875","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"tar","version":"2:1.34-13.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-59875","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59875","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59875","date":"2026-10-08","epss":0.00507,"percentile":0.41325}],"risk":0.26110500000000003,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-59875","description":"A flaw was found in node-tar, a library for manipulating tar archives in Node.js. A remote attacker could craft a malicious archive containing null characters (NUL bytes) in its metadata. When this archive is processed, the unstripped null characters can cause the application to terminate unexpectedly, leading to a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-59875","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59875","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59875","date":"2026-10-08","epss":0.00507,"percentile":0.41325}],"urls":["https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3","https://github.com/isaacs/node-tar/releases/tag/v7.5.17","https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59875","description":"node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17."}]},{"artifact":{"id":"4987714346273301","cpes":["cpe:2.3:a:libssh:libssh:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh:0.10.4-19.el9_8:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:rpm/redhat/libssh@0.10.4-19.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libssh-0.10.4-19.el9_8.src.rpm","type":"rpm","version":"0.10.4-19.el9_8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5372","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libssh","version":"0:0.10.4-19.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-5372","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5372","cwe":"CWE-682","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5372","date":"2026-10-08","epss":0.00501,"percentile":0.40976}],"risk":0.2505,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5372","description":"A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability."},"relatedVulnerabilities":[{"id":"CVE-2025-5372","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5372","cwe":"CWE-682","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5372","date":"2026-10-08","epss":0.00501,"percentile":0.40976}],"urls":["https://access.redhat.com/errata/RHSA-2025:21977","https://access.redhat.com/errata/RHSA-2025:23024","https://access.redhat.com/errata/RHSA-2026:20610","https://access.redhat.com/errata/RHSA-2026:24349","https://access.redhat.com/errata/RHSA-2026:25911","https://access.redhat.com/security/cve/CVE-2025-5372","https://bugzilla.redhat.com/show_bug.cgi?id=2369388"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5372","description":"A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability."}]},{"artifact":{"id":"6b32f79bfc4dbf71","cpes":["cpe:2.3:a:libssh-config:libssh-config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:libssh-config:libssh_config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh-config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh_config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh-config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh_config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh-config:0.10.4-19.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh_config:0.10.4-19.el9_8:*:*:*:*:*:*:*"],"name":"libssh-config","purl":"pkg:rpm/redhat/libssh-config@0.10.4-19.el9_8?arch=noarch&distro=rhel-9.8&upstream=libssh-0.10.4-19.el9_8.src.rpm","type":"rpm","version":"0.10.4-19.el9_8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh","version":"0.10.4-19.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-5372","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libssh","version":"0.10.4-19.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-5372","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5372","cwe":"CWE-682","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5372","date":"2026-10-08","epss":0.00501,"percentile":0.40976}],"risk":0.2505,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5372","description":"A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability."},"relatedVulnerabilities":[{"id":"CVE-2025-5372","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5372","cwe":"CWE-682","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5372","date":"2026-10-08","epss":0.00501,"percentile":0.40976}],"urls":["https://access.redhat.com/errata/RHSA-2025:21977","https://access.redhat.com/errata/RHSA-2025:23024","https://access.redhat.com/errata/RHSA-2026:20610","https://access.redhat.com/errata/RHSA-2026:24349","https://access.redhat.com/errata/RHSA-2026:25911","https://access.redhat.com/security/cve/CVE-2025-5372","https://bugzilla.redhat.com/show_bug.cgi?id=2369388"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5372","description":"A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.24749999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8932","description":"A flaw was found in curl. The libcurl library, used for transferring data with URLs, could improperly reuse existing network connections. This occurred even when changes to mutual Transport Layer Security (mTLS) settings, particularly those for client certificates, should have prevented such reuse. This issue could lead to a security feature bypass, where a client might use a connection with an unintended or weaker security configuration, potentially compromising the integrity or confidentiality of data."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.24749999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8932","description":"A flaw was found in curl. The libcurl library, used for transferring data with URLs, could improperly reuse existing network connections. This occurred even when changes to mutual Transport Layer Security (mTLS) settings, particularly those for client certificates, should have prevented such reuse. This issue could lead to a security feature bypass, where a client might use a connection with an unintended or weaker security configuration, potentially compromising the integrity or confidentiality of data."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"313fc89a99c1b307","cpes":["cpe:2.3:a:libatomic:libatomic:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libatomic:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libatomic","purl":"pkg:rpm/redhat/libatomic@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-46195","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2021-46195","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46195","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-46195","date":"2026-10-08","epss":0.00779,"percentile":0.54517}],"risk":0.24538499999999996,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-46195","description":"A flaw was discovered in the GNU libiberty library within the demangle_path() function in rust-demangle.c, as distributed in the GNU Compiler Collection (GCC). This flaw allows a crafted symbol to cause stack memory to be exhausted, leading to a crash."},"relatedVulnerabilities":[{"id":"CVE-2021-46195","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46195","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-46195","date":"2026-10-08","epss":0.00779,"percentile":0.54517}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=103841"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-46195","description":"GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources."}]},{"artifact":{"id":"23e3d9feac1cb13c","cpes":["cpe:2.3:a:libgcc:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-46195","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2021-46195","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46195","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-46195","date":"2026-10-08","epss":0.00779,"percentile":0.54517}],"risk":0.24538499999999996,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-46195","description":"A flaw was discovered in the GNU libiberty library within the demangle_path() function in rust-demangle.c, as distributed in the GNU Compiler Collection (GCC). This flaw allows a crafted symbol to cause stack memory to be exhausted, leading to a crash."},"relatedVulnerabilities":[{"id":"CVE-2021-46195","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46195","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-46195","date":"2026-10-08","epss":0.00779,"percentile":0.54517}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=103841"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-46195","description":"GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources."}]},{"artifact":{"id":"62a2970ccab3dd86","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-46195","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2021-46195","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46195","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-46195","date":"2026-10-08","epss":0.00779,"percentile":0.54517}],"risk":0.24538499999999996,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-46195","description":"A flaw was discovered in the GNU libiberty library within the demangle_path() function in rust-demangle.c, as distributed in the GNU Compiler Collection (GCC). This flaw allows a crafted symbol to cause stack memory to be exhausted, leading to a crash."},"relatedVulnerabilities":[{"id":"CVE-2021-46195","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-46195","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-46195","date":"2026-10-08","epss":0.00779,"percentile":0.54517}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=103841"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-46195","description":"GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources."}]},{"artifact":{"id":"bb911813b45585f3","cpes":["cpe:2.3:a:perl-AutoLoader:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-AutoLoader:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_AutoLoader:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_AutoLoader:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-AutoLoader","purl":"pkg:rpm/redhat/perl-AutoLoader@5.74-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:5.74-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"7e60fe54e6c09824","cpes":["cpe:2.3:a:perl-B:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-B:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_B:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_B:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-B","purl":"pkg:rpm/redhat/perl-B@1.80-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.80-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"006f5e08bfc4c952","cpes":["cpe:2.3:a:perl-Class-Struct:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class-Struct:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class_Struct:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class_Struct:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Class-Struct","purl":"pkg:rpm/redhat/perl-Class-Struct@0.66-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.66-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"2a9a518a53c7512b","cpes":["cpe:2.3:a:perl-Errno:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Errno:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Errno:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Errno:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Errno","purl":"pkg:rpm/redhat/perl-Errno@1.30-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.30-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"f01ef4b3b3b90538","cpes":["cpe:2.3:a:perl-Fcntl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Fcntl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Fcntl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Fcntl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Fcntl","purl":"pkg:rpm/redhat/perl-Fcntl@1.13-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.13-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"965edf03abd14e95","cpes":["cpe:2.3:a:perl-File-Basename:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File-Basename:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_Basename:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_Basename:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-File-Basename","purl":"pkg:rpm/redhat/perl-File-Basename@2.85-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.85-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"7cb125d521892030","cpes":["cpe:2.3:a:perl-File-stat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File-stat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_stat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_stat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-File-stat","purl":"pkg:rpm/redhat/perl-File-stat@1.09-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.09-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"67e8889d83c474fb","cpes":["cpe:2.3:a:perl-FileHandle:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-FileHandle:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_FileHandle:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_FileHandle:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-FileHandle","purl":"pkg:rpm/redhat/perl-FileHandle@2.03-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.03-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"955cb53aefe39959","cpes":["cpe:2.3:a:perl-Getopt-Std:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt-Std:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt_Std:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt_Std:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Getopt-Std","purl":"pkg:rpm/redhat/perl-Getopt-Std@1.12-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.12-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"e824797a395c58fc","cpes":["cpe:2.3:a:perl-IO:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IO:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IO:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IO:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-IO","purl":"pkg:rpm/redhat/perl-IO@1.43-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.43-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"42816d98549babcf","cpes":["cpe:2.3:a:perl-IPC-Open3:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC-Open3:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC_Open3:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC_Open3:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-IPC-Open3","purl":"pkg:rpm/redhat/perl-IPC-Open3@1.21-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.21-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"7db8a261840c5baa","cpes":["cpe:2.3:a:perl-NDBM-File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM-File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM-File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-NDBM_File","purl":"pkg:rpm/redhat/perl-NDBM_File@1.15-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.15-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"4d811d3afb2547c9","cpes":["cpe:2.3:a:perl-POSIX:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-POSIX:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_POSIX:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_POSIX:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-POSIX","purl":"pkg:rpm/redhat/perl-POSIX@1.94-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.94-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"1bc88a0c5a9ab30a","cpes":["cpe:2.3:a:perl-SelectSaver:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-SelectSaver:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_SelectSaver:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_SelectSaver:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-SelectSaver","purl":"pkg:rpm/redhat/perl-SelectSaver@1.02-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.02-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"449e2b4e3fa8b962","cpes":["cpe:2.3:a:perl-Symbol:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Symbol:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Symbol:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Symbol:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Symbol","purl":"pkg:rpm/redhat/perl-Symbol@1.08-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.08-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"21c1a8a82e4461bf","cpes":["cpe:2.3:a:perl-base:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:rpm/redhat/perl-base@2.27-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.27-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"a0ae61863ea1a76d","cpes":["cpe:2.3:a:perl-if:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-if:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_if:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_if:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-if","purl":"pkg:rpm/redhat/perl-if@0.60.800-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.60.800-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"4ac7ee895d3c99ec","cpes":["cpe:2.3:a:perl-interpreter:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-interpreter:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_interpreter:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_interpreter:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-interpreter","purl":"pkg:rpm/redhat/perl-interpreter@5.32.1-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=4&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"4:5.32.1-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":4,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"bf2c1b6ec909c416","cpes":["cpe:2.3:a:perl-libs:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-libs:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_libs:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_libs:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-libs","purl":"pkg:rpm/redhat/perl-libs@5.32.1-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=4&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"4:5.32.1-484.el9_8","language":"","licenses":["(GPL+ or Artistic) and BSD and HSRL and MIT and UCD and Public domain"],"metadata":{"epoch":4,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"8deef1192afd481d","cpes":["cpe:2.3:a:perl-mro:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-mro:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_mro:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_mro:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-mro","purl":"pkg:rpm/redhat/perl-mro@1.23-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.23-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"9b9db6c4ad38ca1b","cpes":["cpe:2.3:a:perl-overload:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-overload:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overload:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overload:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-overload","purl":"pkg:rpm/redhat/perl-overload@1.31-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.31-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"e12188ce897a6a75","cpes":["cpe:2.3:a:perl-overloading:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-overloading:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overloading:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overloading:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-overloading","purl":"pkg:rpm/redhat/perl-overloading@0.02-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.02-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"103e8134631ed773","cpes":["cpe:2.3:a:perl-subs:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-subs:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_subs:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_subs:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-subs","purl":"pkg:rpm/redhat/perl-subs@1.03-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.03-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"7a082b0e6a9156ba","cpes":["cpe:2.3:a:perl-vars:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-vars:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_vars:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_vars:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-vars","purl":"pkg:rpm/redhat/perl-vars@1.05-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.05-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.24034999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19487","description":"A flaw was found in Perl. The regular expression engine may produce incorrect match results due to a stale failure flag in the Aho-Corasick prescan, which causes it to end prematurely. This can lead to the engine missing valid matches or matching on the wrong branch. As a result, applications that use regular expressions for critical functions like access control or data filtering could make erroneous decisions, potentially leading to security bypasses or unintended information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"2c3aa3a74a1e1b84","cpes":["cpe:2.3:a:libpkgconf:libpkgconf:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libpkgconf:1.7.3-10.el9:*:*:*:*:*:*:*"],"name":"libpkgconf","purl":"pkg:rpm/redhat/libpkgconf@1.7.3-10.el9?arch=x86_64&distro=rhel-9.8&upstream=pkgconf-1.7.3-10.el9.src.rpm","type":"rpm","version":"1.7.3-10.el9","language":"","licenses":["ISC"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pkgconf","version":"1.7.3-10.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-24056","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pkgconf","version":"1.7.3-10.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-24056","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24056","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24056","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24056","date":"2026-10-08","epss":0.00565,"percentile":0.45188}],"risk":0.240125,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-24056","description":"A flaw was found in pkgconf, where a variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. This issue may lead to a buffer overflow, which can crash the software."},"relatedVulnerabilities":[{"id":"CVE-2023-24056","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24056","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24056","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24056","date":"2026-10-08","epss":0.00565,"percentile":0.45188}],"urls":["https://gitea.treehouse.systems/ariadne/pkgconf/commit/628b2b2bafa5d3a2017193ddf375093e70666059","https://github.com/pkgconf/pkgconf/tags","https://nullprogram.com/blog/2023/01/18/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24056","description":"In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes."}]},{"artifact":{"id":"0464bb215cb340f3","cpes":["cpe:2.3:a:pkgconf:pkgconf:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pkgconf:1.7.3-10.el9:*:*:*:*:*:*:*"],"name":"pkgconf","purl":"pkg:rpm/redhat/pkgconf@1.7.3-10.el9?arch=x86_64&distro=rhel-9.8&upstream=pkgconf-1.7.3-10.el9.src.rpm","type":"rpm","version":"1.7.3-10.el9","language":"","licenses":["ISC"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-24056","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pkgconf","version":"0:1.7.3-10.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-24056","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24056","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24056","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24056","date":"2026-10-08","epss":0.00565,"percentile":0.45188}],"risk":0.240125,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-24056","description":"A flaw was found in pkgconf, where a variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. This issue may lead to a buffer overflow, which can crash the software."},"relatedVulnerabilities":[{"id":"CVE-2023-24056","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24056","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24056","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24056","date":"2026-10-08","epss":0.00565,"percentile":0.45188}],"urls":["https://gitea.treehouse.systems/ariadne/pkgconf/commit/628b2b2bafa5d3a2017193ddf375093e70666059","https://github.com/pkgconf/pkgconf/tags","https://nullprogram.com/blog/2023/01/18/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24056","description":"In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes."}]},{"artifact":{"id":"59c097ef22d4b886","cpes":["cpe:2.3:a:pkgconf-m4:pkgconf-m4:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf-m4:pkgconf_m4:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf_m4:pkgconf-m4:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf_m4:pkgconf_m4:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf:pkgconf-m4:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf:pkgconf_m4:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pkgconf-m4:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pkgconf_m4:1.7.3-10.el9:*:*:*:*:*:*:*"],"name":"pkgconf-m4","purl":"pkg:rpm/redhat/pkgconf-m4@1.7.3-10.el9?arch=noarch&distro=rhel-9.8&upstream=pkgconf-1.7.3-10.el9.src.rpm","type":"rpm","version":"1.7.3-10.el9","language":"","licenses":["GPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pkgconf","version":"1.7.3-10.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-24056","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pkgconf","version":"1.7.3-10.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-24056","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24056","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24056","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24056","date":"2026-10-08","epss":0.00565,"percentile":0.45188}],"risk":0.240125,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-24056","description":"A flaw was found in pkgconf, where a variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. This issue may lead to a buffer overflow, which can crash the software."},"relatedVulnerabilities":[{"id":"CVE-2023-24056","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24056","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24056","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24056","date":"2026-10-08","epss":0.00565,"percentile":0.45188}],"urls":["https://gitea.treehouse.systems/ariadne/pkgconf/commit/628b2b2bafa5d3a2017193ddf375093e70666059","https://github.com/pkgconf/pkgconf/tags","https://nullprogram.com/blog/2023/01/18/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24056","description":"In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes."}]},{"artifact":{"id":"edce6e9bd49048cf","cpes":["cpe:2.3:a:pkgconf-pkg-config:pkgconf-pkg-config:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf-pkg-config:pkgconf_pkg_config:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf_pkg_config:pkgconf-pkg-config:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf_pkg_config:pkgconf_pkg_config:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf-pkg:pkgconf-pkg-config:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf-pkg:pkgconf_pkg_config:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf_pkg:pkgconf-pkg-config:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf_pkg:pkgconf_pkg_config:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf:pkgconf-pkg-config:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:pkgconf:pkgconf_pkg_config:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pkgconf-pkg-config:1.7.3-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pkgconf_pkg_config:1.7.3-10.el9:*:*:*:*:*:*:*"],"name":"pkgconf-pkg-config","purl":"pkg:rpm/redhat/pkgconf-pkg-config@1.7.3-10.el9?arch=x86_64&distro=rhel-9.8&upstream=pkgconf-1.7.3-10.el9.src.rpm","type":"rpm","version":"1.7.3-10.el9","language":"","licenses":["ISC"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pkgconf","version":"1.7.3-10.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-24056","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pkgconf","version":"1.7.3-10.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-24056","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24056","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24056","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24056","date":"2026-10-08","epss":0.00565,"percentile":0.45188}],"risk":0.240125,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-24056","description":"A flaw was found in pkgconf, where a variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. This issue may lead to a buffer overflow, which can crash the software."},"relatedVulnerabilities":[{"id":"CVE-2023-24056","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24056","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24056","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24056","date":"2026-10-08","epss":0.00565,"percentile":0.45188}],"urls":["https://gitea.treehouse.systems/ariadne/pkgconf/commit/628b2b2bafa5d3a2017193ddf375093e70666059","https://github.com/pkgconf/pkgconf/tags","https://nullprogram.com/blog/2023/01/18/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24056","description":"In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes."}]},{"artifact":{"id":"86ce7138fbe6d6fd","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vxq7-64xx-v4gw","versionConstraint":">=1.10.3,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-vxq7-64xx-v4gw","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"risk":0.23944000000000001,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw","https://nvd.nist.gov/vuln/detail/CVE-2026-97689","https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vxq7-64xx-v4gw","description":"urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory"},"relatedVulnerabilities":[{"id":"CVE-2026-97689","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"urls":["https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97689","description":"urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.23793,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54873","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by sending specially crafted network packets to a QUIC protocol endpoint. Because the QUIC stack retains memory in packet buffers until the receiving application reads the stream data, an attacker can manipulate data transfers to keep these buffers allocated indefinitely. This behavior leads to excessive memory consumption and can exhaust available system resources."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.23793,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54873","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by sending specially crafted network packets to a QUIC protocol endpoint. Because the QUIC stack retains memory in packet buffers until the receiving application reads the stream data, an attacker can manipulate data transfers to keep these buffers allocated indefinitely. This behavior leads to excessive memory consumption and can exhaust available system resources."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.23793,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54873","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by sending specially crafted network packets to a QUIC protocol endpoint. Because the QUIC stack retains memory in packet buffers until the receiving application reads the stream data, an attacker can manipulate data transfers to keep these buffers allocated indefinitely. This behavior leads to excessive memory consumption and can exhaust available system resources."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-13176","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-13176","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-13176","cwe":"CWE-385","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-13176","date":"2026-10-08","epss":0.00613,"percentile":0.47736}],"risk":0.23600500000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-13176","description":"A timing side-channel vulnerability was found in OpenSSL. This vulnerability allows an attacker to recover the private key. However, measuring the timing would require local access to the signing application or a fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This issue can happen with significant probability only for some of the supported elliptic curves. In particular, the NIST P-521 curve is affected."},"relatedVulnerabilities":[{"id":"CVE-2024-13176","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.1,"impactScore":3.4,"exploitabilityScore":0.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-13176","cwe":"CWE-385","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-13176","date":"2026-10-08","epss":0.00613,"percentile":0.47736}],"urls":["https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844","https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467","https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902","https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65","https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f","https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded","https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86","https://openssl-library.org/news/secadv/20250120.txt","http://www.openwall.com/lists/oss-security/2025/01/20/2","https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html","https://security.netapp.com/advisory/ntap-20250124-0005/","https://security.netapp.com/advisory/ntap-20250418-0010/","https://security.netapp.com/advisory/ntap-20250502-0006/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-13176","description":"Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-13176","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-13176","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-13176","cwe":"CWE-385","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-13176","date":"2026-10-08","epss":0.00613,"percentile":0.47736}],"risk":0.23600500000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-13176","description":"A timing side-channel vulnerability was found in OpenSSL. This vulnerability allows an attacker to recover the private key. However, measuring the timing would require local access to the signing application or a fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This issue can happen with significant probability only for some of the supported elliptic curves. In particular, the NIST P-521 curve is affected."},"relatedVulnerabilities":[{"id":"CVE-2024-13176","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.1,"impactScore":3.4,"exploitabilityScore":0.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-13176","cwe":"CWE-385","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-13176","date":"2026-10-08","epss":0.00613,"percentile":0.47736}],"urls":["https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844","https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467","https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902","https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65","https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f","https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded","https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86","https://openssl-library.org/news/secadv/20250120.txt","http://www.openwall.com/lists/oss-security/2025/01/20/2","https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html","https://security.netapp.com/advisory/ntap-20250124-0005/","https://security.netapp.com/advisory/ntap-20250418-0010/","https://security.netapp.com/advisory/ntap-20250502-0006/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-13176","description":"Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-13176","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-13176","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-13176","cwe":"CWE-385","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-13176","date":"2026-10-08","epss":0.00613,"percentile":0.47736}],"risk":0.23600500000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-13176","description":"A timing side-channel vulnerability was found in OpenSSL. This vulnerability allows an attacker to recover the private key. However, measuring the timing would require local access to the signing application or a fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This issue can happen with significant probability only for some of the supported elliptic curves. In particular, the NIST P-521 curve is affected."},"relatedVulnerabilities":[{"id":"CVE-2024-13176","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.1,"impactScore":3.4,"exploitabilityScore":0.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-13176","cwe":"CWE-385","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-13176","date":"2026-10-08","epss":0.00613,"percentile":0.47736}],"urls":["https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844","https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467","https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902","https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65","https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f","https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded","https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86","https://openssl-library.org/news/secadv/20250120.txt","http://www.openwall.com/lists/oss-security/2025/01/20/2","https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html","https://security.netapp.com/advisory/ntap-20250124-0005/","https://security.netapp.com/advisory/ntap-20250418-0010/","https://security.netapp.com/advisory/ntap-20250502-0006/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-13176","description":"Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue."}]},{"artifact":{"id":"313fc89a99c1b307","cpes":["cpe:2.3:a:libatomic:libatomic:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libatomic:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libatomic","purl":"pkg:rpm/redhat/libatomic@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.230505,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"23e3d9feac1cb13c","cpes":["cpe:2.3:a:libgcc:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.230505,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"62a2970ccab3dd86","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.230505,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"59335e1aab3c3698","cpes":["cpe:2.3:a:python:setuptools:82.0.1:*:*:*:*:*:*:*"],"name":"setuptools","purl":"pkg:pypi/setuptools@82.0.1","type":"python","version":"82.0.1","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/setuptools-82.0.1.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/setuptools-82.0.1.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/setuptools-82.0.1.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/setuptools-82.0.1.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/setuptools-82.0.1.dist-info/top_level.txt","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/setuptools-82.0.1.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"83.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h35f-9h28-mq5c","versionConstraint":"<83.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"setuptools","version":"82.0.1"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-h35f-9h28-mq5c","fix":{"state":"fixed","versions":["83.0.0"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"83.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59890","cwe":"CWE-176","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59890","cwe":"CWE-697","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59890","date":"2026-10-08","epss":0.00405,"percentile":0.32692}],"risk":0.22477499999999997,"urls":["https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c","https://nvd.nist.gov/vuln/detail/CVE-2026-59890","https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f","https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2026-3447.yaml","https://github.com/pypa/setuptools/releases/tag/v83.0.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h35f-9h28-mq5c","description":"setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+"},"relatedVulnerabilities":[{"id":"CVE-2026-59890","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59890","cwe":"CWE-176","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59890","cwe":"CWE-697","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59890","date":"2026-10-08","epss":0.00405,"percentile":0.32692}],"urls":["https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f","https://github.com/pypa/setuptools/releases/tag/v83.0.0","https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59890","description":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0."}]},{"artifact":{"id":"a3c55d7a5e4bf54f","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80489","description":"A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80489","description":"A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80489","description":"A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"a3c55d7a5e4bf54f","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77117","description":"A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77117","description":"A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77117","description":"A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"5249f7f7904b9644","cpes":["cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@46.0.7","type":"python","version":"46.0.7","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"50.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g6cj-pr64-35w5","versionConstraint":">=44.0.0,<50.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"46.0.7"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-g6cj-pr64-35w5","fix":{"state":"fixed","versions":["50.0.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"50.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69247","cwe":"CWE-208","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69247","cwe":"CWE-209","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69247","date":"2026-10-08","epss":0.00274,"percentile":0.18196}],"risk":0.21508999999999995,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5","https://github.com/pyca/cryptography/pull/15369","https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g6cj-pr64-35w5","description":"cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing"},"relatedVulnerabilities":[{"id":"CVE-2026-69247","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69247","cwe":"CWE-208","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69247","cwe":"CWE-209","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69247","date":"2026-10-08","epss":0.00274,"percentile":0.18196}],"urls":["https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f","https://github.com/pyca/cryptography/pull/15369","https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69247","description":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42765","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42765","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42765","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42765","date":"2026-10-08","epss":0.00477,"percentile":0.3919}],"risk":0.21226500000000004,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42765","description":"A flaw was found in OpenSSL. When an application is configured with specific non-default settings for certificate verification, including both Online Certificate Status Protocol (OCSP) response checking and partial chain verification, a NULL dereference can occur. This vulnerability can be triggered if the certificate chain lacks a self-signed trusted anchor, causing the application to crash. This leads to a Denial of Service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-42765","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42765","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42765","date":"2026-10-08","epss":0.00477,"percentile":0.3919}],"urls":["https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334","https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42765","description":"Issue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL dereference\nwill happen if the verified chain does not have a self-signed trusted anchor,\ncrashing the process.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to a\nDenial of Service for an application.\n\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed trusted\nanchor, the issuer will be NULL for the last certificate in the chain. A NULL\npointer dereference then happens.\n\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42765","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42765","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42765","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42765","date":"2026-10-08","epss":0.00477,"percentile":0.3919}],"risk":0.21226500000000004,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42765","description":"A flaw was found in OpenSSL. When an application is configured with specific non-default settings for certificate verification, including both Online Certificate Status Protocol (OCSP) response checking and partial chain verification, a NULL dereference can occur. This vulnerability can be triggered if the certificate chain lacks a self-signed trusted anchor, causing the application to crash. This leads to a Denial of Service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-42765","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42765","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42765","date":"2026-10-08","epss":0.00477,"percentile":0.3919}],"urls":["https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334","https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42765","description":"Issue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL dereference\nwill happen if the verified chain does not have a self-signed trusted anchor,\ncrashing the process.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to a\nDenial of Service for an application.\n\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed trusted\nanchor, the issuer will be NULL for the last certificate in the chain. A NULL\npointer dereference then happens.\n\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42765","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42765","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42765","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42765","date":"2026-10-08","epss":0.00477,"percentile":0.3919}],"risk":0.21226500000000004,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42765","description":"A flaw was found in OpenSSL. When an application is configured with specific non-default settings for certificate verification, including both Online Certificate Status Protocol (OCSP) response checking and partial chain verification, a NULL dereference can occur. This vulnerability can be triggered if the certificate chain lacks a self-signed trusted anchor, causing the application to crash. This leads to a Denial of Service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-42765","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42765","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42765","date":"2026-10-08","epss":0.00477,"percentile":0.3919}],"urls":["https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334","https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42765","description":"Issue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL dereference\nwill happen if the verified chain does not have a self-signed trusted anchor,\ncrashing the process.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to a\nDenial of Service for an application.\n\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed trusted\nanchor, the issuer will be NULL for the last certificate in the chain. A NULL\npointer dereference then happens.\n\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"5249f7f7904b9644","cpes":["cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@46.0.7","type":"python","version":"46.0.7","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"49.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jwv3-5hgf-82ww","versionConstraint":">=42.0.0,<49.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"46.0.7"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-jwv3-5hgf-82ww","fix":{"state":"fixed","versions":["49.0.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"49.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69249","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69249","date":"2026-10-08","epss":0.00252,"percentile":0.15305}],"risk":0.20412,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","https://github.com/pyca/cryptography/pull/14960","https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582","https://nvd.nist.gov/vuln/detail/CVE-2026-69249","https://github.com/pyca/cryptography/commit/3763aa79b","https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3553.yaml"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jwv3-5hgf-82ww","description":"python-cryptography: Duplicate self-signed intermediates can cause exponential path-building"},"relatedVulnerabilities":[{"id":"CVE-2026-69249","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69249","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69249","date":"2026-10-08","epss":0.00252,"percentile":0.15305}],"urls":["https://github.com/pyca/cryptography/commit/3763aa79b","https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582","https://github.com/pyca/cryptography/pull/14960","https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3553.yaml"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69249","description":"python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75806","description":"A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by terminating an active Datagram Transport Layer Security (DTLS) session. By sending an undersized network packet that is shorter than the expected cryptographic overhead, the record processing layer fails to validate the packet length and misinterprets the packet as an internal error rather than an authentication failure. This improper handling triggers a fatal alert that unexpectedly closes the targeted connection without requiring valid encryption keys."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75806","description":"A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by terminating an active Datagram Transport Layer Security (DTLS) session. By sending an undersized network packet that is shorter than the expected cryptographic overhead, the record processing layer fails to validate the packet length and misinterprets the packet as an internal error rather than an authentication failure. This improper handling triggers a fatal alert that unexpectedly closes the targeted connection without requiring valid encryption keys."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75806","description":"A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by terminating an active Datagram Transport Layer Security (DTLS) session. By sending an undersized network packet that is shorter than the expected cryptographic overhead, the record processing layer fails to validate the packet length and misinterprets the packet as an internal error rather than an authentication failure. This improper handling triggers a fatal alert that unexpectedly closes the targeted connection without requiring valid encryption keys."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.19563999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18924","description":"A flaw was found in libcurl. When libcurl handles HTTP/2 Server Push streams and the parent handle shares connections, a use-after-free vulnerability can occur during the cleanup process. This could lead to application crashes, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.19563999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18924","description":"A flaw was found in libcurl. When libcurl handles HTTP/2 Server Push streams and the parent handle shares connections, a use-after-free vulnerability can occur during the cleanup process. This could lead to application crashes, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"e988ae274c693810","cpes":["cpe:2.3:a:redhat:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=tar-1.34-13.el9_8.src.rpm","type":"rpm","version":"2:1.34-13.el9_8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-33056","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"tar","version":"2:1.34-13.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-33056","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33056","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33056","date":"2026-10-08","epss":0.00415,"percentile":0.3379}],"risk":0.19505000000000003,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-33056","description":"A flaw was found in tar-rs, a Rust library for reading and writing tar archives. When unpacking a crafted tar archive, an attacker can exploit a symbolic link vulnerability. By including a symlink followed by a directory with the same name, the library incorrectly applies file permissions to the symlink's target. This allows an attacker to modify the permissions of arbitrary directories outside the intended extraction location."},"relatedVulnerabilities":[{"id":"CVE-2026-33056","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33056","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33056","date":"2026-10-08","epss":0.00415,"percentile":0.3379}],"urls":["https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446","https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33056","description":"tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory — and subsequently apply chmod to it. This allows an attacker to modify the permissions of arbitrary directories outside the extraction root. This issue has been fixed in version 0.4.45."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-1489","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-1489","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1489","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1489","date":"2026-10-08","epss":0.00371,"percentile":0.29003}],"risk":0.19292000000000004,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1489","description":"A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable."},"relatedVulnerabilities":[{"id":"CVE-2026-1489","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1489","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1489","date":"2026-10-08","epss":0.00371,"percentile":0.29003}],"urls":["https://access.redhat.com/security/cve/CVE-2026-1489","https://bugzilla.redhat.com/show_bug.cgi?id=2433348","https://gitlab.gnome.org/GNOME/glib/-/issues/3872","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1489","description":"A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable."}]},{"artifact":{"id":"f3ae9e80296c3638","cpes":["cpe:2.3:a:perl-Socket:perl-Socket:4\\:2.031-4.el9:*:*:*:*:*:*:*","cpe:2.3:a:perl-Socket:perl_Socket:4\\:2.031-4.el9:*:*:*:*:*:*:*","cpe:2.3:a:perl_Socket:perl-Socket:4\\:2.031-4.el9:*:*:*:*:*:*:*","cpe:2.3:a:perl_Socket:perl_Socket:4\\:2.031-4.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Socket:4\\:2.031-4.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Socket:4\\:2.031-4.el9:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Socket:4\\:2.031-4.el9:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Socket:4\\:2.031-4.el9:*:*:*:*:*:*:*"],"name":"perl-Socket","purl":"pkg:rpm/redhat/perl-Socket@2.031-4.el9?arch=x86_64&distro=rhel-9.8&epoch=4&upstream=perl-Socket-2.031-4.el9.src.rpm","type":"rpm","version":"4:2.031-4.el9","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":4,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl-Socket","version":"4:2.031-4.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.19261,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-12087","description":"A flaw was found in the `perl-Socket` component. The `pack_ip_mreq_source()` function, which handles network socket operations, contains an out-of-bounds heap read vulnerability. An attacker providing a specially crafted input can cause the system to read beyond the intended memory buffer, potentially leading to information disclosure from adjacent memory regions."},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"risk":0.18966000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-102633","description":"A flaw was found in expat. On 32-bit systems, an integer overflow occurs within the expat_realloc memory allocation function when calculating buffer sizes. A remote attacker can exploit this vulnerability by supplying specially crafted XML input to an application that processes data with the library. Successful exploitation can lead to a Denial of Service (DoS) or memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"ae70236653f56261","cpes":["cpe:2.3:a:redhat:gawk:5.1.0-6.el9_8.1:*:*:*:*:*:*:*","cpe:2.3:a:gawk:gawk:5.1.0-6.el9_8.1:*:*:*:*:*:*:*"],"name":"gawk","purl":"pkg:rpm/redhat/gawk@5.1.0-6.el9_8.1?arch=x86_64&distro=rhel-9.8&upstream=gawk-5.1.0-6.el9_8.1.src.rpm","type":"rpm","version":"5.1.0-6.el9_8.1","language":"","licenses":["GPLv3+ and GPLv2+ and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-4156","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gawk","version":"0:5.1.0-6.el9_8.1"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-4156","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4156","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4156","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4156","date":"2026-10-08","epss":0.00415,"percentile":0.33778}],"risk":0.188825,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-4156","description":"A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2023-4156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4156","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-4156","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-4156","date":"2026-10-08","epss":0.00415,"percentile":0.33778}],"urls":["https://access.redhat.com/security/cve/CVE-2023-4156","https://bugzilla.redhat.com/show_bug.cgi?id=2215930"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4156","description":"A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4873","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4873","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"risk":0.184885,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4873","description":"A flaw was found in curl. A remote attacker could exploit this by initiating an unencrypted connection (via IMAP, SMTP, or POP3) and then making a subsequent request to the same host that requires Transport Layer Security (TLS). Due to incorrect connection reuse, the subsequent request would bypass the TLS requirement, leading to the transmission of sensitive information in cleartext. This vulnerability, categorized as Cleartext Transmission of Sensitive Information (CWE-319), results in information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-4873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4873","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4873","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"risk":0.184885,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4873","description":"A flaw was found in curl. A remote attacker could exploit this by initiating an unencrypted connection (via IMAP, SMTP, or POP3) and then making a subsequent request to the same host that requires Transport Layer Security (TLS). Due to incorrect connection reuse, the subsequent request would bypass the TLS requirement, leading to the transmission of sensitive information in cleartext. This vulnerability, categorized as Cleartext Transmission of Sensitive Information (CWE-319), results in information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-4873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15224","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-15224","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15224","date":"2026-10-08","epss":0.0048,"percentile":0.39438}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15224","description":"A flaw was found in libcurl. When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent."},"relatedVulnerabilities":[{"id":"CVE-2025-15224","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15224","date":"2026-10-08","epss":0.0048,"percentile":0.39438}],"urls":["https://curl.se/docs/CVE-2025-15224.html","https://curl.se/docs/CVE-2025-15224.json","https://hackerone.com/reports/3480925","http://www.openwall.com/lists/oss-security/2026/01/07/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15224","description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15224","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-15224","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15224","date":"2026-10-08","epss":0.0048,"percentile":0.39438}],"risk":0.1848,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15224","description":"A flaw was found in libcurl. When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent."},"relatedVulnerabilities":[{"id":"CVE-2025-15224","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15224","date":"2026-10-08","epss":0.0048,"percentile":0.39438}],"urls":["https://curl.se/docs/CVE-2025-15224.html","https://curl.se/docs/CVE-2025-15224.json","https://hackerone.com/reports/3480925","http://www.openwall.com/lists/oss-security/2026/01/07/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15224","description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent."}]},{"artifact":{"id":"5249f7f7904b9644","cpes":["cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@46.0.7","type":"python","version":"46.0.7","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"49.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m2h6-j472-rp4c","versionConstraint":">=45.0.0,<49.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"46.0.7"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-m2h6-j472-rp4c","fix":{"state":"fixed","versions":["49.0.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"49.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69248","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69248","date":"2026-10-08","epss":0.00309,"percentile":0.21751}],"risk":0.183855,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c","https://github.com/pyca/cryptography/pull/14888","https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2","https://nvd.nist.gov/vuln/detail/CVE-2026-69248","https://github.com/pyca/cryptography/commit/286c89128","https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3554.yaml"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m2h6-j472-rp4c","description":"python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees"},"relatedVulnerabilities":[{"id":"CVE-2026-69248","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69248","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69248","date":"2026-10-08","epss":0.00309,"percentile":0.21751}],"urls":["https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2","https://github.com/pyca/cryptography/pull/14888","https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69248","description":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0."}]},{"artifact":{"id":"86ce7138fbe6d6fd","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8988-9cw3-xx77","versionConstraint":">=1.26.0,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-8988-9cw3-xx77","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97687","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-97687","cwe":"CWE-440","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97687","date":"2026-10-08","epss":0.00242,"percentile":0.14092}],"risk":0.18270999999999998,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77","https://nvd.nist.gov/vuln/detail/CVE-2026-97687","https://github.com/urllib3/urllib3/pull/5093","https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465","https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8988-9cw3-xx77","description":"urllib3: HTTPS proxy TLS configuration may be ignored or overridden"},"relatedVulnerabilities":[{"id":"CVE-2026-97687","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97687","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-97687","cwe":"CWE-440","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97687","date":"2026-10-08","epss":0.00242,"percentile":0.14092}],"urls":["https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465","https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3","https://github.com/urllib3/urllib3/pull/5093","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97687","description":"urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"8cf05c8343d9a4a8","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.5.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0989","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0989","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0989","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0989","date":"2026-10-08","epss":0.00538,"percentile":0.43534}],"risk":0.18023,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0989","description":"A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk."},"relatedVulnerabilities":[{"id":"CVE-2026-0989","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0989","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0989","date":"2026-10-08","epss":0.00538,"percentile":0.43534}],"urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-0989","https://bugzilla.redhat.com/show_bug.cgi?id=2429933","https://gitlab.gnome.org/GNOME/libxml2/-/issues/998"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0989","description":"A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating a denial-of-service risk."}]},{"artifact":{"id":"a3c55d7a5e4bf54f","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8674","description":"A flaw was found in the GNU C Library (glibc) DNS stub resolver. This vulnerability allows a remote attacker on the local network to cause a denial of service by providing a specially crafted, excessively long search domain. When the resolver attempts to initialize with this long domain from /etc/resolv.conf or the LOCALDOMAIN environment variable, it triggers an assertion failure, which aborts the process. This can be exploited without privileges on the target system, potentially through network configuration mechanisms like DHCP or a VPN server."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8674","description":"A flaw was found in the GNU C Library (glibc) DNS stub resolver. This vulnerability allows a remote attacker on the local network to cause a denial of service by providing a specially crafted, excessively long search domain. When the resolver attempts to initialize with this long domain from /etc/resolv.conf or the LOCALDOMAIN environment variable, it triggers an assertion failure, which aborts the process. This can be exploited without privileges on the target system, potentially through network configuration mechanisms like DHCP or a VPN server."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8674","description":"A flaw was found in the GNU C Library (glibc) DNS stub resolver. This vulnerability allows a remote attacker on the local network to cause a denial of service by providing a specially crafted, excessively long search domain. When the resolver attempts to initialize with this long domain from /etc/resolv.conf or the LOCALDOMAIN environment variable, it triggers an assertion failure, which aborts the process. This can be exploited without privileges on the target system, potentially through network configuration mechanisms like DHCP or a VPN server."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"86ce7138fbe6d6fd","cpes":["cpe:2.3:a:python:urllib3:2.7.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.7.0","type":"python","version":"2.7.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/urllib3-2.7.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gh4c-6fx4-qh6g","versionConstraint":">=2.6.2,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.7.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-gh4c-6fx4-qh6g","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97688","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97688","date":"2026-10-08","epss":0.00291,"percentile":0.19899}],"risk":0.173145,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g","https://nvd.nist.gov/vuln/detail/CVE-2026-97688","https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gh4c-6fx4-qh6g","description":"urllib3: Chunked Deflate streaming can enter an infinite loop"},"relatedVulnerabilities":[{"id":"CVE-2026-97688","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97688","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97688","date":"2026-10-08","epss":0.00291,"percentile":0.19899}],"urls":["https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97688","description":"urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42772","description":"A flaw was found in OpenSSL. A remote attacker who establishes a QUIC network connection can cause a Denial of Service (DoS) by sending specially sequenced, out-of-order stream frames. Because the stream reassembly mechanism handles non-sequential data fragments inefficiently, processing these frames forces the server to consume excessive CPU resources. Consequently, an attacker can exhaust system processing capacity using minimal network bandwidth."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42772","description":"A flaw was found in OpenSSL. A remote attacker who establishes a QUIC network connection can cause a Denial of Service (DoS) by sending specially sequenced, out-of-order stream frames. Because the stream reassembly mechanism handles non-sequential data fragments inefficiently, processing these frames forces the server to consume excessive CPU resources. Consequently, an attacker can exhaust system processing capacity using minimal network bandwidth."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42772","description":"A flaw was found in OpenSSL. A remote attacker who establishes a QUIC network connection can cause a Denial of Service (DoS) by sending specially sequenced, out-of-order stream frames. Because the stream reassembly mechanism handles non-sequential data fragments inefficiently, processing these frames forces the server to consume excessive CPU resources. Consequently, an attacker can exhaust system processing capacity using minimal network bandwidth."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"965c5108ab84fcf4","cpes":["cpe:2.3:a:gnupg2:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*"],"name":"gnupg2","purl":"pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=rhel-9.8&upstream=gnupg2-2.3.3-5.el9_7.src.rpm","type":"rpm","version":"2.3.3-5.el9_7","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-24883","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnupg2","version":"0:2.3.3-5.el9_7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-24883","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24883","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-24883","date":"2026-10-08","epss":0.00498,"percentile":0.40726}],"risk":0.16683,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-24883","description":"A flaw was found in GnuPG. A remote attacker could provide a specially crafted long signature packet that, when processed, causes the application to crash. This vulnerability leads to a denial of service (DoS), making the GnuPG application unavailable to legitimate users."},"relatedVulnerabilities":[{"id":"CVE-2026-24883","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24883","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-24883","date":"2026-10-08","epss":0.00498,"percentile":0.40726}],"urls":["https://dev.gnupg.org/T8049","https://www.openwall.com/lists/oss-security/2026/01/27/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24883","description":"In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash)."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.16157000000000002,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-103111","description":"A flaw was found in pcre2. When an application processes attacker-controlled regular expressions using certain Just-In-Time (JIT) compiler interfaces, an out-of-bounds write with arbitrary data can occur. An attacker could exploit this vulnerability to achieve arbitrary code execution, corrupt memory, or cause a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.16157000000000002,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-103111","description":"A flaw was found in pcre2. When an application processes attacker-controlled regular expressions using certain Just-In-Time (JIT) compiler interfaces, an out-of-bounds write with arbitrary data can occur. An attacker could exploit this vulnerability to achieve arbitrary code execution, corrupt memory, or cause a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-1484","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-1484","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1484","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1484","date":"2026-10-08","epss":0.00346,"percentile":0.26123}],"risk":0.15916,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1484","description":"A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably."},"relatedVulnerabilities":[{"id":"CVE-2026-1484","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1484","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1484","date":"2026-10-08","epss":0.00346,"percentile":0.26123}],"urls":["https://access.redhat.com/security/cve/CVE-2026-1484","https://bugzilla.redhat.com/show_bug.cgi?id=2433259","https://gitlab.gnome.org/GNOME/glib/-/issues/3870","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1484","description":"A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-3360","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-3360","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-3360","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-3360","date":"2026-10-08","epss":0.00475,"percentile":0.39072}],"risk":0.159125,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-3360","description":"A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function."},"relatedVulnerabilities":[{"id":"CVE-2025-3360","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-3360","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-3360","date":"2026-10-08","epss":0.00475,"percentile":0.39072}],"urls":["https://access.redhat.com/security/cve/CVE-2025-3360","https://bugzilla.redhat.com/show_bug.cgi?id=2357754","https://gitlab.gnome.org/GNOME/glib/-/issues/3647","https://lists.debian.org/debian-lts-announce/2025/04/msg00024.html","https://gitlab.gnome.org/GNOME/glib/-/work_items/3647"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-3360","description":"A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function."}]},{"artifact":{"id":"c558b7cb26630788","cpes":["cpe:2.3:a:pip_developers_\\<distutils_sig_project:python-pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:python_pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python-pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:python_pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig_project:pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python-pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:python_pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python-pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:python_pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sigproject:pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip-developers-\\<distutils-sig:pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip_developers_\\<distutils_sig:pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python-pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:python_pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python-pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:python_pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:python:python-pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:python:python_pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python-pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pypa:python_pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip:python-pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip:python_pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:python-pip:pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:python_pip:pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:python:pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pypa:pip:26.1.2:*:*:*:*:*:*:*","cpe:2.3:a:pip:pip:26.1.2:*:*:*:*:*:*:*"],"name":"pip","purl":"pkg:pypi/pip@26.1.2","type":"python","version":"26.1.2","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/pip-26.1.2.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/pip-26.1.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/pip-26.1.2.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/pip-26.1.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"26.2.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qwm4-qh6w-59xr","versionConstraint":"<26.2.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pip","version":"26.1.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-qwm4-qh6w-59xr","fix":{"state":"fixed","versions":["26.2.0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"26.2.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":5.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-13346","date":"2026-10-08","epss":0.00292,"percentile":0.19984}],"risk":0.15476,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-13346","https://github.com/pypa/pip/pull/14110","https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX","http://www.openwall.com/lists/oss-security/2026/07/29/7","https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679","https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2026-3721.yaml"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qwm4-qh6w-59xr","description":"pip would incorrectly handle doubly-encoded package URLs from indexes"},"relatedVulnerabilities":[{"id":"CVE-2026-13346","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-13346","date":"2026-10-08","epss":0.00292,"percentile":0.19984}],"urls":["https://github.com/pypa/pip/pull/14110","https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/","http://www.openwall.com/lists/oss-security/2026/07/29/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13346","description":"pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time."}]},{"artifact":{"id":"313fc89a99c1b307","cpes":["cpe:2.3:a:libatomic:libatomic:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libatomic:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libatomic","purl":"pkg:rpm/redhat/libatomic@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.15,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"23e3d9feac1cb13c","cpes":["cpe:2.3:a:libgcc:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.15,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"62a2970ccab3dd86","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:11.5.0-14.el9:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@11.5.0-14.el9?arch=x86_64&distro=rhel-9.8&upstream=gcc-11.5.0-14.el9.src.rpm","type":"rpm","version":"11.5.0-14.el9","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"11.5.0-14.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gcc","version":"11.5.0-14.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"risk":0.15,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-08","epss":0.0025,"percentile":0.14937}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"57d863142a15e7aa","cpes":["cpe:2.3:a:cyrus-sasl-lib:cyrus-sasl-lib:2.1.27-22.el9:*:*:*:*:*:*:*","cpe:2.3:a:cyrus-sasl-lib:cyrus_sasl_lib:2.1.27-22.el9:*:*:*:*:*:*:*","cpe:2.3:a:cyrus_sasl_lib:cyrus-sasl-lib:2.1.27-22.el9:*:*:*:*:*:*:*","cpe:2.3:a:cyrus_sasl_lib:cyrus_sasl_lib:2.1.27-22.el9:*:*:*:*:*:*:*","cpe:2.3:a:cyrus-sasl:cyrus-sasl-lib:2.1.27-22.el9:*:*:*:*:*:*:*","cpe:2.3:a:cyrus-sasl:cyrus_sasl_lib:2.1.27-22.el9:*:*:*:*:*:*:*","cpe:2.3:a:cyrus_sasl:cyrus-sasl-lib:2.1.27-22.el9:*:*:*:*:*:*:*","cpe:2.3:a:cyrus_sasl:cyrus_sasl_lib:2.1.27-22.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:cyrus-sasl-lib:2.1.27-22.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:cyrus_sasl_lib:2.1.27-22.el9:*:*:*:*:*:*:*","cpe:2.3:a:cyrus:cyrus-sasl-lib:2.1.27-22.el9:*:*:*:*:*:*:*","cpe:2.3:a:cyrus:cyrus_sasl_lib:2.1.27-22.el9:*:*:*:*:*:*:*"],"name":"cyrus-sasl-lib","purl":"pkg:rpm/redhat/cyrus-sasl-lib@2.1.27-22.el9?arch=x86_64&distro=rhel-9.8&upstream=cyrus-sasl-2.1.27-22.el9.src.rpm","type":"rpm","version":"2.1.27-22.el9","language":"","licenses":["BSD with advertising"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"cyrus-sasl","version":"2.1.27-22.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107161","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"cyrus-sasl","version":"2.1.27-22.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-107161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"risk":0.14875000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."},"relatedVulnerabilities":[{"id":"CVE-2026-107161","cvss":[{"type":"Primary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107161","cwe":"CWE-122","type":"Primary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-107161","date":"2026-10-08","epss":0.00238,"percentile":0.136}],"urls":["https://access.redhat.com/security/cve/CVE-2026-107161","https://bugzilla.redhat.com/show_bug.cgi?id=2460420"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107161","description":"A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not recompute that size when quoting (escaping special characters) makes the value longer. The under-sized buffer is then passed to strcat(), causing a heap-based out-of-bounds write whose size depends on attacker-controlled input. A malicious or on-path DIGEST-MD5 (or HTTP Digest) server can trigger this flaw in a connecting client by supplying a crafted challenge field, such as realm or nonce, most likely resulting in a crash of the client application."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.14873,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89157","description":"A flaw was found in PCRE2. On 32-bit platforms, an attacker can provide a specially crafted large pattern, leading to an out-of-bounds write within the pcre2_pattern_convert function. This vulnerability can result in high integrity impact, such as data corruption, and potentially a low availability impact, causing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.14873,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89157","description":"A flaw was found in PCRE2. On 32-bit platforms, an attacker can provide a specially crafted large pattern, leading to an out-of-bounds write within the pcre2_pattern_convert function. This vulnerability can result in high integrity impact, such as data corruption, and potentially a low availability impact, causing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0988","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0988","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0988","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0988","date":"2026-10-08","epss":0.00441,"percentile":0.36292}],"risk":0.14773499999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0988","description":"A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-0988","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0988","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0988","date":"2026-10-08","epss":0.00441,"percentile":0.36292}],"urls":["https://access.redhat.com/errata/RHSA-2026:7461","https://access.redhat.com/security/cve/CVE-2026-0988","https://bugzilla.redhat.com/show_bug.cgi?id=2429886","https://gitlab.gnome.org/GNOME/glib/-/issues/3851"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0988","description":"A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS)."}]},{"artifact":{"id":"1c9a349fe96f859f","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=sqlite-3.34.1-11.el9_8.src.rpm","type":"rpm","version":"3.34.1-11.el9_8","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite","version":"3.34.1-11.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-0232","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"sqlite","version":"3.34.1-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2024-0232","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0232","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-0232","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-0232","date":"2026-10-08","epss":0.00381,"percentile":0.29975}],"risk":0.146685,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-0232","description":"A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2024-0232","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0232","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-0232","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-0232","date":"2026-10-08","epss":0.00381,"percentile":0.29975}],"urls":["https://access.redhat.com/security/cve/CVE-2024-0232","https://bugzilla.redhat.com/show_bug.cgi?id=2243754","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7/","https://security.netapp.com/advisory/ntap-20240315-0007/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-0232","description":"A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.14497000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-72897","description":"A flaw was found in openssl. When a server replaces its security context during an active Transport Layer Security (TLS) handshake, it fails to update the internal capacity tracking for cryptographic signature algorithms. A remote peer can exploit this issue by advertising specific signature algorithms, causing out-of-bounds memory reads and writes on the server heap. This vulnerability can corrupt internal memory and terminate the process, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.14497000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-72897","description":"A flaw was found in openssl. When a server replaces its security context during an active Transport Layer Security (TLS) handshake, it fails to update the internal capacity tracking for cryptographic signature algorithms. A remote peer can exploit this issue by advertising specific signature algorithms, causing out-of-bounds memory reads and writes on the server heap. This vulnerability can corrupt internal memory and terminate the process, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.14497000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-72897","description":"A flaw was found in openssl. When a server replaces its security context during an active Transport Layer Security (TLS) handshake, it fails to update the internal capacity tracking for cryptographic signature algorithms. A remote peer can exploit this issue by advertising specific signature algorithms, causing out-of-bounds memory reads and writes on the server heap. This vulnerability can corrupt internal memory and terminate the process, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.14333500000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54872","description":"A flaw was found in OpenSSL. A timing side-channel vulnerability in generic elliptic curve scalar multiplication allows an attacker to recover private cryptographic keys. When performing signature operations, such as the Elliptic Curve Digital Signature Algorithm (ECDSA) or SM2, using curves without dedicated constant-time implementations, variations in processing time leak information about the per-signature secret value. By measuring the duration of numerous signing operations, an attacker can analyze these timing differences to reconstruct the private signing key."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.14333500000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54872","description":"A flaw was found in OpenSSL. A timing side-channel vulnerability in generic elliptic curve scalar multiplication allows an attacker to recover private cryptographic keys. When performing signature operations, such as the Elliptic Curve Digital Signature Algorithm (ECDSA) or SM2, using curves without dedicated constant-time implementations, variations in processing time leak information about the per-signature secret value. By measuring the duration of numerous signing operations, an attacker can analyze these timing differences to reconstruct the private signing key."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.14333500000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54872","description":"A flaw was found in OpenSSL. A timing side-channel vulnerability in generic elliptic curve scalar multiplication allows an attacker to recover private cryptographic keys. When performing signature operations, such as the Elliptic Curve Digital Signature Algorithm (ECDSA) or SM2, using curves without dedicated constant-time implementations, variations in processing time leak information about the per-signature secret value. By measuring the duration of numerous signing operations, an attacker can analyze these timing differences to reconstruct the private signing key."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-31789","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-31789","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"risk":0.143,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-31789","description":"A flaw was found in OpenSSL. This vulnerability, a heap buffer overflow, affects 32-bit systems when processing an unusually large X.509 certificate. If an application or service attempts to print or log such a specially crafted certificate, it could lead to a system crash or potentially allow an attacker to execute arbitrary code. This issue is considered low severity due to the specific conditions required for exploitation, including the need for an extremely large certificate and a 32-bit operating environment."},"relatedVulnerabilities":[{"id":"CVE-2026-31789","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"urls":["https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde","https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf","https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49","https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9","https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31789","description":"Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-31789","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-31789","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"risk":0.143,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-31789","description":"A flaw was found in OpenSSL. This vulnerability, a heap buffer overflow, affects 32-bit systems when processing an unusually large X.509 certificate. If an application or service attempts to print or log such a specially crafted certificate, it could lead to a system crash or potentially allow an attacker to execute arbitrary code. This issue is considered low severity due to the specific conditions required for exploitation, including the need for an extremely large certificate and a 32-bit operating environment."},"relatedVulnerabilities":[{"id":"CVE-2026-31789","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"urls":["https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde","https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf","https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49","https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9","https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31789","description":"Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-31789","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-31789","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"risk":0.143,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-31789","description":"A flaw was found in OpenSSL. This vulnerability, a heap buffer overflow, affects 32-bit systems when processing an unusually large X.509 certificate. If an application or service attempts to print or log such a specially crafted certificate, it could lead to a system crash or potentially allow an attacker to execute arbitrary code. This issue is considered low severity due to the specific conditions required for exploitation, including the need for an extremely large certificate and a 32-bit operating environment."},"relatedVulnerabilities":[{"id":"CVE-2026-31789","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"urls":["https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde","https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf","https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49","https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9","https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31789","description":"Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.14259,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54875","description":"A flaw was found in OpenSSL. The optimized scalar point multiplication used for SM2 cryptographic operations on ARM64 and RISC-V architectures does not execute in constant time. An attacker capable of measuring execution times or observing processor cache-access patterns can exploit this side channel during decryption or digital signature generation. This vulnerability allows the attacker to deduce sensitive private keys or signature nonces, leading to information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.14259,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54875","description":"A flaw was found in OpenSSL. The optimized scalar point multiplication used for SM2 cryptographic operations on ARM64 and RISC-V architectures does not execute in constant time. An attacker capable of measuring execution times or observing processor cache-access patterns can exploit this side channel during decryption or digital signature generation. This vulnerability allows the attacker to deduce sensitive private keys or signature nonces, leading to information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.14259,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54875","description":"A flaw was found in OpenSSL. The optimized scalar point multiplication used for SM2 cryptographic operations on ARM64 and RISC-V architectures does not execute in constant time. An attacker capable of measuring execution times or observing processor cache-access patterns can exploit this side channel during decryption or digital signature generation. This vulnerability allows the attacker to deduce sensitive private keys or signature nonces, leading to information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.14202499999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89158","description":"A flaw was found in PCRE2. On 32-bit platforms, an integer overflow in the `pcre2_compile_32` function can lead to an out-of-bounds write. This vulnerability could allow a remote attacker to achieve a high integrity impact and a low availability impact, potentially leading to data corruption or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.14202499999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89158","description":"A flaw was found in PCRE2. On 32-bit platforms, an integer overflow in the `pcre2_compile_32` function can lead to an out-of-bounds write. This vulnerability could allow a remote attacker to achieve a high integrity impact and a low availability impact, potentially leading to data corruption or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-13034","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-13034","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13034","date":"2026-10-08","epss":0.00239,"percentile":0.13699}],"risk":0.14101,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-13034","description":"A flaw was found in curl. When configured to use public key pinning with QUIC connections and GnuTLS, and with standard certificate verification explicitly disabled, curl could bypass the intended public key check. This oversight allows a malicious server to impersonate a legitimate one, potentially leading to unauthorized access or information disclosure due to a failure in verifying the server's identity."},"relatedVulnerabilities":[{"id":"CVE-2025-13034","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13034","date":"2026-10-08","epss":0.00239,"percentile":0.13699}],"urls":["https://curl.se/docs/CVE-2025-13034.html","https://curl.se/docs/CVE-2025-13034.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13034","description":"When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-13034","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-13034","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13034","date":"2026-10-08","epss":0.00239,"percentile":0.13699}],"risk":0.14101,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-13034","description":"A flaw was found in curl. When configured to use public key pinning with QUIC connections and GnuTLS, and with standard certificate verification explicitly disabled, curl could bypass the intended public key check. This oversight allows a malicious server to impersonate a legitimate one, potentially leading to unauthorized access or information disclosure due to a failure in verifying the server's identity."},"relatedVulnerabilities":[{"id":"CVE-2025-13034","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13034","date":"2026-10-08","epss":0.00239,"percentile":0.13699}],"urls":["https://curl.se/docs/CVE-2025-13034.html","https://curl.se/docs/CVE-2025-13034.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13034","description":"When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification."}]},{"artifact":{"id":"036832cd701a5ff1","cpes":["cpe:2.3:a:perl-URI:perl-URI:5.09-3.el9:*:*:*:*:*:*:*","cpe:2.3:a:perl-URI:perl_URI:5.09-3.el9:*:*:*:*:*:*:*","cpe:2.3:a:perl_URI:perl-URI:5.09-3.el9:*:*:*:*:*:*:*","cpe:2.3:a:perl_URI:perl_URI:5.09-3.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-URI:5.09-3.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_URI:5.09-3.el9:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-URI:5.09-3.el9:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_URI:5.09-3.el9:*:*:*:*:*:*:*"],"name":"perl-URI","purl":"pkg:rpm/redhat/perl-URI@5.09-3.el9?arch=noarch&distro=rhel-9.8&upstream=perl-URI-5.09-3.el9.src.rpm","type":"rpm","version":"5.09-3.el9","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19953","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl-URI","version":"0:5.09-3.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19953","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19953","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19953","date":"2026-10-08","epss":0.00229,"percentile":0.1262}],"risk":0.13969,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19953","description":"A flaw was found in the URI component for Perl. This vulnerability occurs because the `nameprep` function, responsible for encoding hostnames, does not properly normalize Unicode characters. As a result, a hostname that is not in a standard Unicode form (non-NFC) can be encoded into a non-standard label. This discrepancy can lead to a situation where security checks, such as allow lists or Server-Side Request Forgery (SSRF) filters, may incorrectly process hostnames, potentially allowing an attacker to bypass security restrictions."},"relatedVulnerabilities":[{"id":"CVE-2026-19953","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19953","cwe":"CWE-1289","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19953","date":"2026-10-08","epss":0.00229,"percentile":0.1262}],"urls":["https://github.com/libwww-perl/URI/commit/956619a9e94f86d8d2c529b4e06a3674c54a73e7.patch","https://github.com/libwww-perl/URI/pull/191","https://metacpan.org/release/OALDERS/URI-5.36/changes","https://www.rfc-editor.org/rfc/rfc5891#section-5.2","http://www.openwall.com/lists/oss-security/2026/08/31/14"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19953","description":"URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep.\n\nnameprep lowercases each host label but performs no Unicode normalization. IDNA requires a label to be normalized to Form C before it is encoded (RFC 5891), so a label that is not already in NFC is encoded to a different A-label than its normalized form. A label built from the precomposed Devanagari sequence U+0958 U+093E encodes to xn--72b5c without normalization but to xn--11b2fg after NFC normalization, and xn--72b5c does not round-trip back to the original label.\n\nAny caller that reads host() from a URI built from untrusted input and uses it for a security decision (an allow or deny list, an SSRF filter, deduplication, a cache key) sees the non-standard label, while a client that fetches the same URL resolves the NFC form, so the check and the fetch can disagree about the host."}]},{"artifact":{"id":"e23cfc4398093f3b","cpes":["cpe:2.3:a:diffutils:diffutils:3.7-12.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:diffutils:3.7-12.el9:*:*:*:*:*:*:*"],"name":"diffutils","purl":"pkg:rpm/redhat/diffutils@3.7-12.el9?arch=x86_64&distro=rhel-9.8&upstream=diffutils-3.7-12.el9.src.rpm","type":"rpm","version":"3.7-12.el9","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53910","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"diffutils","version":"0:3.7-12.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53910","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53910","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-53910","date":"2026-10-08","epss":0.00332,"percentile":0.24312}],"risk":0.13778,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53910","description":"A flaw was found in the diff3 program in the diffutils package. When processing specially crafted diff output, a heap-based buffer overflow can occur due to multiple signed integer overflows in line-mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds, resulting in a denial of service or memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-53910","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53910","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-53910","date":"2026-10-08","epss":0.00332,"percentile":0.24312}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-53910","https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50","https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815","https://git.savannah.gnu.org/cgit/diffutils.git/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53910","description":"diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds.\nWhen processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing. \nAn attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.\n\n\nThis issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815 \n\nNOTE:\nThe project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges."}]},{"artifact":{"id":"8cf05c8343d9a4a8","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.5.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0992","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-0992","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0992","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0992","date":"2026-10-08","epss":0.00465,"percentile":0.38301}],"risk":0.137175,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0992","description":"A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition."},"relatedVulnerabilities":[{"id":"CVE-2026-0992","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0992","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0992","date":"2026-10-08","epss":0.00465,"percentile":0.38301}],"urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-0992","https://bugzilla.redhat.com/show_bug.cgi?id=2429975","https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0992","description":"A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU consumption and degrades application availability, resulting in a denial-of-service condition."}]},{"artifact":{"id":"bb911813b45585f3","cpes":["cpe:2.3:a:perl-AutoLoader:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-AutoLoader:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_AutoLoader:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_AutoLoader:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-AutoLoader","purl":"pkg:rpm/redhat/perl-AutoLoader@5.74-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:5.74-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"7e60fe54e6c09824","cpes":["cpe:2.3:a:perl-B:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-B:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_B:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_B:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-B","purl":"pkg:rpm/redhat/perl-B@1.80-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.80-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"006f5e08bfc4c952","cpes":["cpe:2.3:a:perl-Class-Struct:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class-Struct:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class_Struct:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class_Struct:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Class-Struct","purl":"pkg:rpm/redhat/perl-Class-Struct@0.66-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.66-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"2a9a518a53c7512b","cpes":["cpe:2.3:a:perl-Errno:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Errno:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Errno:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Errno:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Errno","purl":"pkg:rpm/redhat/perl-Errno@1.30-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.30-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"f01ef4b3b3b90538","cpes":["cpe:2.3:a:perl-Fcntl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Fcntl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Fcntl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Fcntl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Fcntl","purl":"pkg:rpm/redhat/perl-Fcntl@1.13-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.13-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"965edf03abd14e95","cpes":["cpe:2.3:a:perl-File-Basename:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File-Basename:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_Basename:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_Basename:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-File-Basename","purl":"pkg:rpm/redhat/perl-File-Basename@2.85-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.85-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"7cb125d521892030","cpes":["cpe:2.3:a:perl-File-stat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File-stat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_stat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_stat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-File-stat","purl":"pkg:rpm/redhat/perl-File-stat@1.09-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.09-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"67e8889d83c474fb","cpes":["cpe:2.3:a:perl-FileHandle:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-FileHandle:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_FileHandle:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_FileHandle:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-FileHandle","purl":"pkg:rpm/redhat/perl-FileHandle@2.03-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.03-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"955cb53aefe39959","cpes":["cpe:2.3:a:perl-Getopt-Std:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt-Std:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt_Std:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt_Std:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Getopt-Std","purl":"pkg:rpm/redhat/perl-Getopt-Std@1.12-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.12-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"e824797a395c58fc","cpes":["cpe:2.3:a:perl-IO:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IO:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IO:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IO:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-IO","purl":"pkg:rpm/redhat/perl-IO@1.43-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.43-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"42816d98549babcf","cpes":["cpe:2.3:a:perl-IPC-Open3:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC-Open3:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC_Open3:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC_Open3:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-IPC-Open3","purl":"pkg:rpm/redhat/perl-IPC-Open3@1.21-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.21-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"7db8a261840c5baa","cpes":["cpe:2.3:a:perl-NDBM-File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM-File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM-File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-NDBM_File","purl":"pkg:rpm/redhat/perl-NDBM_File@1.15-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.15-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"4d811d3afb2547c9","cpes":["cpe:2.3:a:perl-POSIX:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-POSIX:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_POSIX:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_POSIX:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-POSIX","purl":"pkg:rpm/redhat/perl-POSIX@1.94-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.94-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"1bc88a0c5a9ab30a","cpes":["cpe:2.3:a:perl-SelectSaver:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-SelectSaver:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_SelectSaver:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_SelectSaver:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-SelectSaver","purl":"pkg:rpm/redhat/perl-SelectSaver@1.02-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.02-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"449e2b4e3fa8b962","cpes":["cpe:2.3:a:perl-Symbol:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Symbol:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Symbol:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Symbol:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Symbol","purl":"pkg:rpm/redhat/perl-Symbol@1.08-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.08-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"21c1a8a82e4461bf","cpes":["cpe:2.3:a:perl-base:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:rpm/redhat/perl-base@2.27-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.27-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"a0ae61863ea1a76d","cpes":["cpe:2.3:a:perl-if:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-if:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_if:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_if:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-if","purl":"pkg:rpm/redhat/perl-if@0.60.800-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.60.800-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"4ac7ee895d3c99ec","cpes":["cpe:2.3:a:perl-interpreter:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-interpreter:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_interpreter:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_interpreter:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-interpreter","purl":"pkg:rpm/redhat/perl-interpreter@5.32.1-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=4&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"4:5.32.1-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":4,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"bf2c1b6ec909c416","cpes":["cpe:2.3:a:perl-libs:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-libs:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_libs:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_libs:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-libs","purl":"pkg:rpm/redhat/perl-libs@5.32.1-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=4&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"4:5.32.1-484.el9_8","language":"","licenses":["(GPL+ or Artistic) and BSD and HSRL and MIT and UCD and Public domain"],"metadata":{"epoch":4,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"8deef1192afd481d","cpes":["cpe:2.3:a:perl-mro:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-mro:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_mro:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_mro:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-mro","purl":"pkg:rpm/redhat/perl-mro@1.23-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.23-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"9b9db6c4ad38ca1b","cpes":["cpe:2.3:a:perl-overload:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-overload:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overload:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overload:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-overload","purl":"pkg:rpm/redhat/perl-overload@1.31-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.31-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"e12188ce897a6a75","cpes":["cpe:2.3:a:perl-overloading:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-overloading:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overloading:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overloading:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-overloading","purl":"pkg:rpm/redhat/perl-overloading@0.02-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.02-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"103e8134631ed773","cpes":["cpe:2.3:a:perl-subs:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-subs:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_subs:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_subs:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-subs","purl":"pkg:rpm/redhat/perl-subs@1.03-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.03-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"7a082b0e6a9156ba","cpes":["cpe:2.3:a:perl-vars:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-vars:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_vars:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_vars:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-vars","purl":"pkg:rpm/redhat/perl-vars@1.05-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.05-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15534","description":"A flaw was found in Perl. An integer overflow vulnerability in the regular expression engine's superlinear cache calculation can lead to out-of-bounds memory reads and writes. A remote attacker could exploit this by providing a specially crafted, large input string during regular expression matching. This could result in a denial of service (DoS) due to a process crash or potentially lead to heap memory corruption, enabling arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"7e23f8149f581507","cpes":["cpe:2.3:a:krb5-libs:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5-libs:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5_libs:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5_libs:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*"],"name":"krb5-libs","purl":"pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=rhel-9.8&upstream=krb5-1.21.1-10.el9_8.src.rpm","type":"rpm","version":"1.21.1-10.el9_8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5","version":"1.21.1-10.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"krb5","version":"1.21.1-10.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-11850","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-08","epss":0.00271,"percentile":0.17713}],"risk":0.1355,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."},"relatedVulnerabilities":[{"id":"CVE-2026-11850","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-08","epss":0.00271,"percentile":0.17713}],"urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."}]},{"artifact":{"id":"965c5108ab84fcf4","cpes":["cpe:2.3:a:gnupg2:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*"],"name":"gnupg2","purl":"pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=rhel-9.8&upstream=gnupg2-2.3.3-5.el9_7.src.rpm","type":"rpm","version":"2.3.3-5.el9_7","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnupg2","version":"0:2.3.3-5.el9_7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.13477999999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-3219","description":"A vulnerability was found in GnuPG. GnuPG can spin on a relatively small input by crafting a public key with thousands of signatures attached and compressed down to a few kilobytes. This issue can potentially cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41080","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-41080","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"risk":0.13333,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-41080","description":"A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing a specially crafted XML document that leverages insufficient entropy in the hash function. This can lead to hash flooding, a type of Denial of Service (DoS) attack, where the system becomes unresponsive or crashes due to excessive resource consumption."},"relatedVulnerabilities":[{"id":"CVE-2026-41080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41080","cwe":"CWE-331","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41080","date":"2026-10-08","epss":0.00398,"percentile":0.31902}],"urls":["https://blog.hartwork.org/posts/expat-2-8-0-released/","https://github.com/libexpat/libexpat/issues/47","https://github.com/libexpat/libexpat/pull/1183","https://www.openwall.com/lists/oss-security/2026/04/26/1","http://www.openwall.com/lists/oss-security/2026/04/26/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41080","description":"libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-7039","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-7039","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7039","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-7039","date":"2026-10-08","epss":0.00397,"percentile":0.31786}],"risk":0.13299499999999997,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-7039","description":"A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations."},"relatedVulnerabilities":[{"id":"CVE-2025-7039","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7039","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-7039","date":"2026-10-08","epss":0.00397,"percentile":0.31786}],"urls":["https://access.redhat.com/security/cve/CVE-2025-7039","https://bugzilla.redhat.com/show_bug.cgi?id=2392423","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7039","description":"A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.132435,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77696","description":"A flaw was found in OpenSSL. During SM2 signature generation, variable-time arithmetic operations are performed on secret values, creating an observable timing side-channel. An attacker capable of measuring signature generation times can collect timing data across multiple signing operations, which may allow them to recover the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.132435,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77696","description":"A flaw was found in OpenSSL. During SM2 signature generation, variable-time arithmetic operations are performed on secret values, creating an observable timing side-channel. An attacker capable of measuring signature generation times can collect timing data across multiple signing operations, which may allow them to recover the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.132435,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77696","description":"A flaw was found in OpenSSL. During SM2 signature generation, variable-time arithmetic operations are performed on secret values, creating an observable timing side-channel. An attacker capable of measuring signature generation times can collect timing data across multiple signing operations, which may allow them to recover the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"e1b413eca8446714","cpes":["cpe:2.3:a:libarchive:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libarchive-3.5.3-11.el9_8.src.rpm","type":"rpm","version":"3.5.3-11.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5918","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libarchive","version":"0:3.5.3-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-5918","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5918","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5918","date":"2026-10-08","epss":0.00368,"percentile":0.28592}],"risk":0.12696,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5918","description":"A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition."},"relatedVulnerabilities":[{"id":"CVE-2025-5918","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":6.6,"impactScore":5.2,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5918","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5918","date":"2026-10-08","epss":0.00368,"percentile":0.28592}],"urls":["https://access.redhat.com/security/cve/CVE-2025-5918","https://bugzilla.redhat.com/show_bug.cgi?id=2370877","https://github.com/libarchive/libarchive/pull/2584","https://github.com/libarchive/libarchive/releases/tag/v3.8.0"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5918","description":"A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.12428499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80230","description":"A flaw was found in libcurl, a client-side URL transfer library. When public key pinning is configured, but standard peer verification is explicitly disabled, libcurl incorrectly allows connections to proceed without enforcing the public key pinning. This bypass enables unauthenticated connections that should have been rejected, potentially compromising the integrity of the connection."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.12428499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80230","description":"A flaw was found in libcurl, a client-side URL transfer library. When public key pinning is configured, but standard peer verification is explicitly disabled, libcurl incorrectly allows connections to proceed without enforcing the public key pinning. This bypass enables unauthenticated connections that should have been rejected, potentially compromising the integrity of the connection."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"8cf05c8343d9a4a8","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.13-14.el9_8.5:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.13-14.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=libxml2-2.9.13-14.el9_8.5.src.rpm","type":"rpm","version":"2.9.13-14.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-1757","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libxml2","version":"0:2.9.13-14.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-1757","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1757","cwe":"CWE-401","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1757","date":"2026-10-08","epss":0.00221,"percentile":0.11581}],"risk":0.12376000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1757","description":"A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system."},"relatedVulnerabilities":[{"id":"CVE-2026-1757","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1757","cwe":"CWE-401","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1757","date":"2026-10-08","epss":0.00221,"percentile":0.11581}],"urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-1757","https://bugzilla.redhat.com/show_bug.cgi?id=2435940","https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1757","description":"A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84783","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-84783","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84783","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84783","date":"2026-10-08","epss":0.00226,"percentile":0.12197}],"risk":0.12317,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84783","description":"A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by initiating concurrent connections to a multi-threaded Transport Layer Security (TLS) client or server verifying certificates. Due to improper synchronization when multiple threads simultaneously decode and cache certificate extensions for a shared Certificate Authority (CA) certificate, cached memory can be freed while still in use by another thread. This use-after-free condition results in an invalid memory read, causing the application to crash."},"relatedVulnerabilities":[{"id":"CVE-2026-84783","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84783","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84783","date":"2026-10-08","epss":0.00226,"percentile":0.12197}],"urls":["https://github.com/openssl/openssl/commit/de97a1a54f43edefd43b5084ecac54ecadb33081","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84783","description":"Issue summary: The first concurrent use of the same X.509 certificate by\nseveral threads may cause its cached extension data to be freed while\nanother thread is still using it.\n\nImpact summary: A remote, unauthenticated peer could crash a multi-threaded\nTLS client, or a multi-threaded TLS server that requests client\ncertificates, if the first certificate chains built to the same trusted CA\ncertificate are built by several connections at the same time. This is a\nuse-after-free read, which is likely to crash the process, resulting in a\nDenial of Service.\n\nCWE: CWE-416: Use After Free\n\nDescription: OpenSSL caches the decoded values of a certificate's X.509v3\nextensions inside the X509 object the first time they are needed. In\nOpenSSL 4.0 this cache is built in two phases: the extension values are\ncomputed while holding a read lock on the certificate, and the results are\nthen installed into the certificate under a write lock. Because a read lock\ndoes not exclude other readers, several threads can compute the cache for\nthe same certificate at the same time. Each thread that subsequently\nacquires the write lock installs its own results and frees the values\ninstalled by the thread before it, even though that earlier thread has\nalready marked the cache as complete and may have returned pointers into it\nto its caller. A caller still using those pointers then reads freed memory.\n\nAny certificate shared between threads is exposed the first time its\nextensions are decoded. In TLS the certificates at risk are the trusted CA\ncertificates supplied for chain verification, by whatever means, since these\nare shared by every connection and their extensions are decoded and cached\nthe first time a chain is built to them. Certificates sent by the peer are\ndecoded separately for each connection and are not shared, so they are not\naffected. In a TLS client verifying server certificates, or a TLS server\nthat requests and verifies client certificates, the use-after-free could\nonly occur if the first chains built to the same trusted CA are built by\nseveral connections at the same time.\n\nFIPS impact: no\nThe FIPS module is not affected as X.509 certificate handling is outside\nof the OpenSSL FIPS module boundary.\n\nOpenSSL 4.0 is vulnerable to this issue.\n\nOpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\n\nThis issue was reported on 27 August 2026 by Tim Becker (Xint.io) and\nindependently in a public report on 31 August 2026 by aydinmercan.\n\nThe fix has been developed by Bob Beck.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Tim Becker (Xint.io), aydinmercan\nFixed by: Bob Beck"}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84783","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-84783","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84783","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84783","date":"2026-10-08","epss":0.00226,"percentile":0.12197}],"risk":0.12317,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84783","description":"A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by initiating concurrent connections to a multi-threaded Transport Layer Security (TLS) client or server verifying certificates. Due to improper synchronization when multiple threads simultaneously decode and cache certificate extensions for a shared Certificate Authority (CA) certificate, cached memory can be freed while still in use by another thread. This use-after-free condition results in an invalid memory read, causing the application to crash."},"relatedVulnerabilities":[{"id":"CVE-2026-84783","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84783","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84783","date":"2026-10-08","epss":0.00226,"percentile":0.12197}],"urls":["https://github.com/openssl/openssl/commit/de97a1a54f43edefd43b5084ecac54ecadb33081","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84783","description":"Issue summary: The first concurrent use of the same X.509 certificate by\nseveral threads may cause its cached extension data to be freed while\nanother thread is still using it.\n\nImpact summary: A remote, unauthenticated peer could crash a multi-threaded\nTLS client, or a multi-threaded TLS server that requests client\ncertificates, if the first certificate chains built to the same trusted CA\ncertificate are built by several connections at the same time. This is a\nuse-after-free read, which is likely to crash the process, resulting in a\nDenial of Service.\n\nCWE: CWE-416: Use After Free\n\nDescription: OpenSSL caches the decoded values of a certificate's X.509v3\nextensions inside the X509 object the first time they are needed. In\nOpenSSL 4.0 this cache is built in two phases: the extension values are\ncomputed while holding a read lock on the certificate, and the results are\nthen installed into the certificate under a write lock. Because a read lock\ndoes not exclude other readers, several threads can compute the cache for\nthe same certificate at the same time. Each thread that subsequently\nacquires the write lock installs its own results and frees the values\ninstalled by the thread before it, even though that earlier thread has\nalready marked the cache as complete and may have returned pointers into it\nto its caller. A caller still using those pointers then reads freed memory.\n\nAny certificate shared between threads is exposed the first time its\nextensions are decoded. In TLS the certificates at risk are the trusted CA\ncertificates supplied for chain verification, by whatever means, since these\nare shared by every connection and their extensions are decoded and cached\nthe first time a chain is built to them. Certificates sent by the peer are\ndecoded separately for each connection and are not shared, so they are not\naffected. In a TLS client verifying server certificates, or a TLS server\nthat requests and verifies client certificates, the use-after-free could\nonly occur if the first chains built to the same trusted CA are built by\nseveral connections at the same time.\n\nFIPS impact: no\nThe FIPS module is not affected as X.509 certificate handling is outside\nof the OpenSSL FIPS module boundary.\n\nOpenSSL 4.0 is vulnerable to this issue.\n\nOpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\n\nThis issue was reported on 27 August 2026 by Tim Becker (Xint.io) and\nindependently in a public report on 31 August 2026 by aydinmercan.\n\nThe fix has been developed by Bob Beck.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Tim Becker (Xint.io), aydinmercan\nFixed by: Bob Beck"}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84783","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-84783","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84783","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84783","date":"2026-10-08","epss":0.00226,"percentile":0.12197}],"risk":0.12317,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84783","description":"A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by initiating concurrent connections to a multi-threaded Transport Layer Security (TLS) client or server verifying certificates. Due to improper synchronization when multiple threads simultaneously decode and cache certificate extensions for a shared Certificate Authority (CA) certificate, cached memory can be freed while still in use by another thread. This use-after-free condition results in an invalid memory read, causing the application to crash."},"relatedVulnerabilities":[{"id":"CVE-2026-84783","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84783","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84783","date":"2026-10-08","epss":0.00226,"percentile":0.12197}],"urls":["https://github.com/openssl/openssl/commit/de97a1a54f43edefd43b5084ecac54ecadb33081","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84783","description":"Issue summary: The first concurrent use of the same X.509 certificate by\nseveral threads may cause its cached extension data to be freed while\nanother thread is still using it.\n\nImpact summary: A remote, unauthenticated peer could crash a multi-threaded\nTLS client, or a multi-threaded TLS server that requests client\ncertificates, if the first certificate chains built to the same trusted CA\ncertificate are built by several connections at the same time. This is a\nuse-after-free read, which is likely to crash the process, resulting in a\nDenial of Service.\n\nCWE: CWE-416: Use After Free\n\nDescription: OpenSSL caches the decoded values of a certificate's X.509v3\nextensions inside the X509 object the first time they are needed. In\nOpenSSL 4.0 this cache is built in two phases: the extension values are\ncomputed while holding a read lock on the certificate, and the results are\nthen installed into the certificate under a write lock. Because a read lock\ndoes not exclude other readers, several threads can compute the cache for\nthe same certificate at the same time. Each thread that subsequently\nacquires the write lock installs its own results and frees the values\ninstalled by the thread before it, even though that earlier thread has\nalready marked the cache as complete and may have returned pointers into it\nto its caller. A caller still using those pointers then reads freed memory.\n\nAny certificate shared between threads is exposed the first time its\nextensions are decoded. In TLS the certificates at risk are the trusted CA\ncertificates supplied for chain verification, by whatever means, since these\nare shared by every connection and their extensions are decoded and cached\nthe first time a chain is built to them. Certificates sent by the peer are\ndecoded separately for each connection and are not shared, so they are not\naffected. In a TLS client verifying server certificates, or a TLS server\nthat requests and verifies client certificates, the use-after-free could\nonly occur if the first chains built to the same trusted CA are built by\nseveral connections at the same time.\n\nFIPS impact: no\nThe FIPS module is not affected as X.509 certificate handling is outside\nof the OpenSSL FIPS module boundary.\n\nOpenSSL 4.0 is vulnerable to this issue.\n\nOpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\n\nThis issue was reported on 27 August 2026 by Tim Becker (Xint.io) and\nindependently in a public report on 31 August 2026 by aydinmercan.\n\nThe fix has been developed by Bob Beck.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Tim Becker (Xint.io), aydinmercan\nFixed by: Bob Beck"}]},{"artifact":{"id":"a3c55d7a5e4bf54f","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89092","description":"A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, causing it to crash and leading to degraded DNS resolution for the system. There is also a remote possibility of nscd cache corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89092","description":"A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, causing it to crash and leading to degraded DNS resolution for the system. There is also a remote possibility of nscd cache corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89092","description":"A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, causing it to crash and leading to degraded DNS resolution for the system. There is also a remote possibility of nscd cache corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"d0a796bfde79311d","cpes":["cpe:2.3:a:python-virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:virtualenv:21.5.1:*:*:*:*:*:*:*"],"name":"virtualenv","purl":"pkg:pypi/virtualenv@21.5.1","type":"python","version":"21.5.1","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"21.7.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-94p9-xgh2-xp45","versionConstraint":"<=21.7.11 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"virtualenv","version":"21.5.1"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-94p9-xgh2-xp45","fix":{"state":"fixed","versions":["21.7.12"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"21.7.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102930","cwe":"CWE-494","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102930","date":"2026-10-08","epss":0.0016,"percentile":0.04545}],"risk":0.12160000000000001,"urls":["https://github.com/pypa/virtualenv/security/advisories/GHSA-94p9-xgh2-xp45","https://nvd.nist.gov/vuln/detail/CVE-2026-102930","https://github.com/pypa/virtualenv/pull/3251","https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d","https://github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4011.yaml","https://github.com/pypa/virtualenv","https://github.com/pypa/virtualenv/releases/tag/21.7.12","https://pypi.org/project/virtualenv"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-94p9-xgh2-xp45","description":"virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use"},"relatedVulnerabilities":[{"id":"CVE-2026-102930","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102930","cwe":"CWE-494","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102930","date":"2026-10-08","epss":0.0016,"percentile":0.04545}],"urls":["https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d","https://github.com/pypa/virtualenv/pull/3251","https://github.com/pypa/virtualenv/security/advisories/GHSA-94p9-xgh2-xp45"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102930","description":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes against an authoritative digest equivalent to the embedded wheels' BUNDLE_SHA256 verification. A compromised index, stale mirror, or intercepted TLS connection can substitute a different wheel under the requested distribution, version, and filename, after which virtualenv caches and seeds the attacker-controlled wheel into subsequently created environments. The verification applies to the default PyPI path and is intentionally skipped when PIP_INDEX_URL, PIP_EXTRA_INDEX_URL, or PIP_INDEX configures a custom index that may legitimately publish rebuilt wheels. This issue is fixed in version 21.7.12."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.12099000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75805","description":"A flaw was found in OpenSSL. When a Certificate Management Protocol (CMP) client requests certificate revocation using a PKCS#10 Certificate Signing Request (CSR), it omits the certificate issuer name and serial number. A malicious or compromised CMP server, or an attacker possessing valid message protection credentials, can exploit this flaw by returning a crafted revocation response. This triggers a NULL pointer dereference when the client attempts to compare response data, causing the client application to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.12099000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75805","description":"A flaw was found in OpenSSL. When a Certificate Management Protocol (CMP) client requests certificate revocation using a PKCS#10 Certificate Signing Request (CSR), it omits the certificate issuer name and serial number. A malicious or compromised CMP server, or an attacker possessing valid message protection credentials, can exploit this flaw by returning a crafted revocation response. This triggers a NULL pointer dereference when the client attempts to compare response data, causing the client application to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.12099000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75805","description":"A flaw was found in OpenSSL. When a Certificate Management Protocol (CMP) client requests certificate revocation using a PKCS#10 Certificate Signing Request (CSR), it omits the certificate issuer name and serial number. A malicious or compromised CMP server, or an attacker possessing valid message protection credentials, can exploit this flaw by returning a crafted revocation response. This triggers a NULL pointer dereference when the client attempts to compare response data, causing the client application to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"a3c55d7a5e4bf54f","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.11990000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6791","description":"A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.11990000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6791","description":"A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.11990000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6791","description":"A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-35191","description":"A flaw was found in OpenSSL. This vulnerability allows a remote attacker to abuse the server to amplify network traffic in a Denial of Service (DoS) attack. When the server is configured without client address validation, incoming datagrams containing multiple QUIC packets cause the server to calculate credit limits incorrectly by adding the total datagram size for each packet. Consequently, the server exceeds standard rate limits and transmits excessive response data to spoofed target addresses."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-35191","description":"A flaw was found in OpenSSL. This vulnerability allows a remote attacker to abuse the server to amplify network traffic in a Denial of Service (DoS) attack. When the server is configured without client address validation, incoming datagrams containing multiple QUIC packets cause the server to calculate credit limits incorrectly by adding the total datagram size for each packet. Consequently, the server exceeds standard rate limits and transmits excessive response data to spoofed target addresses."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-35191","description":"A flaw was found in OpenSSL. This vulnerability allows a remote attacker to abuse the server to amplify network traffic in a Denial of Service (DoS) attack. When the server is configured without client address validation, incoming datagrams containing multiple QUIC packets cause the server to calculate credit limits incorrectly by adding the total datagram size for each packet. Consequently, the server exceeds standard rate limits and transmits excessive response data to spoofed target addresses."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"6b29b8ef2f83cc22","cpes":["cpe:2.3:a:redhat:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm","purl":"pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78367","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"0:4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-78367","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857}],"risk":0.11819999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-78367","description":"A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb)."},"relatedVulnerabilities":[{"id":"CVE-2026-78367","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857}],"urls":["https://access.redhat.com/security/cve/CVE-2026-78367","https://bugzilla.redhat.com/show_bug.cgi?id=2521857","https://github.com/rpm-software-management/rpm/issues/4314"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78367","description":"A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb)."}]},{"artifact":{"id":"108e4bcd5f0cf305","cpes":["cpe:2.3:a:rpm-libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm-libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm-libs","purl":"pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.16.1.3-40.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78367","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-78367","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857}],"risk":0.11819999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-78367","description":"A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb)."},"relatedVulnerabilities":[{"id":"CVE-2026-78367","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78367","cwe":"CWE-94","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78367","date":"2026-10-08","epss":0.00197,"percentile":0.0857}],"urls":["https://access.redhat.com/security/cve/CVE-2026-78367","https://bugzilla.redhat.com/show_bug.cgi?id=2521857","https://github.com/rpm-software-management/rpm/issues/4314"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78367","description":"A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execution with the privileges of the user running rpmbuild. This can be exploited when a victim or automated build system processes an attacker-controlled source tarball using rpmbuild tarball mode (such as -ts, -ta, or -tb)."}]},{"artifact":{"id":"d0a796bfde79311d","cpes":["cpe:2.3:a:python-virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:virtualenv:21.5.1:*:*:*:*:*:*:*"],"name":"virtualenv","purl":"pkg:pypi/virtualenv@21.5.1","type":"python","version":"21.5.1","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"21.7.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p58f-9548-mpm2","versionConstraint":"<=21.7.12 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"virtualenv","version":"21.5.1"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-p58f-9548-mpm2","fix":{"state":"fixed","versions":["21.7.13"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"21.7.13"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102925","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102925","date":"2026-10-08","epss":0.00153,"percentile":0.03865}],"risk":0.117045,"urls":["https://github.com/pypa/virtualenv/security/advisories/GHSA-p58f-9548-mpm2","https://nvd.nist.gov/vuln/detail/CVE-2026-102925","https://github.com/pypa/virtualenv/pull/3252","https://github.com/pypa/virtualenv/commit/4d5a105ec2a2723b8c7f4571bb68f4f71d01e3f6","https://github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4013.yaml","https://github.com/pypa/virtualenv","https://github.com/pypa/virtualenv/releases/tag/21.7.13","https://pypi.org/project/virtualenv"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p58f-9548-mpm2","description":"virtualenv bash and fish activation scripts execute commands embedded in paths"},"relatedVulnerabilities":[{"id":"CVE-2026-102925","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102925","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102925","date":"2026-10-08","epss":0.00153,"percentile":0.03865}],"urls":["https://github.com/pypa/virtualenv/commit/4d5a105ec2a2723b8c7f4571bb68f4f71d01e3f6","https://github.com/pypa/virtualenv/pull/3252","https://github.com/pypa/virtualenv/releases/tag/21.7.13","https://github.com/pypa/virtualenv/security/advisories/GHSA-p58f-9548-mpm2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102925","description":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path reaches __VIRTUAL_ENV__ when a relocated environment's recorded directory is absent; in the fish script, crafted Tcl or Tk library paths reach __TCL_LIBRARY__ or __TK_LIBRARY__. The surplus quotes can terminate the data-only quoted run and leave shell metacharacters parsed as commands when a user sources the activation script, allowing code execution with that user's privileges. This issue is fixed in version 21.7.13."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"risk":0.11691499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6276","description":"A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom `Host:` header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new `Host:` header. This can lead to libcurl incorrectly sending cookies intended for the first host to the second host, resulting in a cookie leak. This issue is categorized as an Origin Validation Error (CWE-346). Exploitation typically requires specific debugging configurations."},"relatedVulnerabilities":[{"id":"CVE-2026-6276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"risk":0.11691499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6276","description":"A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom `Host:` header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new `Host:` header. This can lead to libcurl incorrectly sending cookies intended for the first host to the second host, resulting in a cookie leak. This issue is categorized as an Origin Validation Error (CWE-346). Exploitation typically requires specific debugging configurations."},"relatedVulnerabilities":[{"id":"CVE-2026-6276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.11376499999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-82209","description":"A flaw was found in libcurl when libpsl support is enabled. A remote attacker could exploit this vulnerability by setting a `Set-Cookie` header with a `Domain` attribute that explicitly matches a public suffix. This improper handling causes libcurl to save the cookie with a wildcard domain scope, leading to the cookie being inappropriately sent to arbitrary sibling subdomains under the same public suffix. This could result in sensitive information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.11376499999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-82209","description":"A flaw was found in libcurl when libpsl support is enabled. A remote attacker could exploit this vulnerability by setting a `Set-Cookie` header with a `Domain` attribute that explicitly matches a public suffix. This improper handling causes libcurl to save the cookie with a wildcard domain scope, leading to the cookie being inappropriately sent to arbitrary sibling subdomains under the same public suffix. This could result in sensitive information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"e1b413eca8446714","cpes":["cpe:2.3:a:libarchive:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libarchive-3.5.3-11.el9_8.src.rpm","type":"rpm","version":"3.5.3-11.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-1632","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libarchive","version":"0:3.5.3-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-1632","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1632","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1632","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1632","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1632","date":"2026-10-08","epss":0.00342,"percentile":0.25659}],"risk":0.10772999999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-1632","description":"A flaw was found in the bsdunzip utility of libarchive. In affected versions, a specially crafted file may trigger a null pointer dereference. This issue can lead to an application crash or other unexpected behavior. This bug does not compromise the integrity or availability of the base system."},"relatedVulnerabilities":[{"id":"CVE-2025-1632","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-1632","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1632","cwe":"CWE-476","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-1632","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-1632","date":"2026-10-08","epss":0.00342,"percentile":0.25659}],"urls":["https://github.com/Ekkosun/pocs/blob/main/bsdunzip-poc","https://vuldb.com/?ctiid.296619","https://vuldb.com/?id.296619","https://vuldb.com/?submit.496460"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-1632","description":"A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."}]},{"artifact":{"id":"bb911813b45585f3","cpes":["cpe:2.3:a:perl-AutoLoader:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-AutoLoader:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_AutoLoader:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_AutoLoader:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_AutoLoader:0\\:5.74-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-AutoLoader","purl":"pkg:rpm/redhat/perl-AutoLoader@5.74-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:5.74-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"7e60fe54e6c09824","cpes":["cpe:2.3:a:perl-B:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-B:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_B:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_B:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_B:0\\:1.80-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-B","purl":"pkg:rpm/redhat/perl-B@1.80-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.80-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"006f5e08bfc4c952","cpes":["cpe:2.3:a:perl-Class-Struct:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class-Struct:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class_Struct:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class_Struct:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Class:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Class:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Class-Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Class_Struct:0\\:0.66-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Class-Struct","purl":"pkg:rpm/redhat/perl-Class-Struct@0.66-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.66-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"2a9a518a53c7512b","cpes":["cpe:2.3:a:perl-Errno:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Errno:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Errno:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Errno:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Errno:0\\:1.30-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Errno","purl":"pkg:rpm/redhat/perl-Errno@1.30-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.30-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"f01ef4b3b3b90538","cpes":["cpe:2.3:a:perl-Fcntl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Fcntl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Fcntl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Fcntl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Fcntl:0\\:1.13-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Fcntl","purl":"pkg:rpm/redhat/perl-Fcntl@1.13-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.13-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"965edf03abd14e95","cpes":["cpe:2.3:a:perl-File-Basename:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File-Basename:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_Basename:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_Basename:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-File-Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_File_Basename:0\\:2.85-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-File-Basename","purl":"pkg:rpm/redhat/perl-File-Basename@2.85-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.85-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"7cb125d521892030","cpes":["cpe:2.3:a:perl-File-stat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File-stat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_stat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File_stat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-File:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_File:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-File-stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_File_stat:0\\:1.09-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-File-stat","purl":"pkg:rpm/redhat/perl-File-stat@1.09-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.09-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"67e8889d83c474fb","cpes":["cpe:2.3:a:perl-FileHandle:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-FileHandle:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_FileHandle:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_FileHandle:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_FileHandle:0\\:2.03-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-FileHandle","purl":"pkg:rpm/redhat/perl-FileHandle@2.03-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.03-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"955cb53aefe39959","cpes":["cpe:2.3:a:perl-Getopt-Std:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt-Std:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt_Std:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt_Std:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Getopt:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Getopt:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Getopt-Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Getopt_Std:0\\:1.12-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Getopt-Std","purl":"pkg:rpm/redhat/perl-Getopt-Std@1.12-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.12-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"e824797a395c58fc","cpes":["cpe:2.3:a:perl-IO:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IO:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IO:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IO:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_IO:0\\:1.43-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-IO","purl":"pkg:rpm/redhat/perl-IO@1.43-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.43-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"42816d98549babcf","cpes":["cpe:2.3:a:perl-IPC-Open3:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC-Open3:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC_Open3:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC_Open3:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-IPC:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_IPC:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-IPC-Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_IPC_Open3:0\\:1.21-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-IPC-Open3","purl":"pkg:rpm/redhat/perl-IPC-Open3@1.21-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.21-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"7db8a261840c5baa","cpes":["cpe:2.3:a:perl-NDBM-File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM-File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM-File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM_File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM_File:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-NDBM:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_NDBM:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-NDBM-File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_NDBM_File:0\\:1.15-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-NDBM_File","purl":"pkg:rpm/redhat/perl-NDBM_File@1.15-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.15-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"4d811d3afb2547c9","cpes":["cpe:2.3:a:perl-POSIX:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-POSIX:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_POSIX:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_POSIX:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_POSIX:0\\:1.94-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-POSIX","purl":"pkg:rpm/redhat/perl-POSIX@1.94-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.94-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"1bc88a0c5a9ab30a","cpes":["cpe:2.3:a:perl-SelectSaver:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-SelectSaver:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_SelectSaver:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_SelectSaver:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_SelectSaver:0\\:1.02-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-SelectSaver","purl":"pkg:rpm/redhat/perl-SelectSaver@1.02-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.02-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"449e2b4e3fa8b962","cpes":["cpe:2.3:a:perl-Symbol:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-Symbol:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Symbol:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_Symbol:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_Symbol:0\\:1.08-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-Symbol","purl":"pkg:rpm/redhat/perl-Symbol@1.08-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.08-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"21c1a8a82e4461bf","cpes":["cpe:2.3:a:perl-base:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:0\\:2.27-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:rpm/redhat/perl-base@2.27-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:2.27-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"a0ae61863ea1a76d","cpes":["cpe:2.3:a:perl-if:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-if:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_if:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_if:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_if:0\\:0.60.800-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-if","purl":"pkg:rpm/redhat/perl-if@0.60.800-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.60.800-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"4ac7ee895d3c99ec","cpes":["cpe:2.3:a:perl-interpreter:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-interpreter:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_interpreter:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_interpreter:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_interpreter:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-interpreter","purl":"pkg:rpm/redhat/perl-interpreter@5.32.1-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=4&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"4:5.32.1-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":4,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"bf2c1b6ec909c416","cpes":["cpe:2.3:a:perl-libs:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-libs:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_libs:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_libs:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_libs:4\\:5.32.1-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-libs","purl":"pkg:rpm/redhat/perl-libs@5.32.1-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=4&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"4:5.32.1-484.el9_8","language":"","licenses":["(GPL+ or Artistic) and BSD and HSRL and MIT and UCD and Public domain"],"metadata":{"epoch":4,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"8deef1192afd481d","cpes":["cpe:2.3:a:perl-mro:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-mro:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_mro:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_mro:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_mro:0\\:1.23-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-mro","purl":"pkg:rpm/redhat/perl-mro@1.23-484.el9_8?arch=x86_64&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.23-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"9b9db6c4ad38ca1b","cpes":["cpe:2.3:a:perl-overload:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-overload:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overload:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overload:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_overload:0\\:1.31-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-overload","purl":"pkg:rpm/redhat/perl-overload@1.31-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.31-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"e12188ce897a6a75","cpes":["cpe:2.3:a:perl-overloading:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-overloading:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overloading:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_overloading:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_overloading:0\\:0.02-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-overloading","purl":"pkg:rpm/redhat/perl-overloading@0.02-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:0.02-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"103e8134631ed773","cpes":["cpe:2.3:a:perl-subs:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-subs:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_subs:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_subs:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_subs:0\\:1.03-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-subs","purl":"pkg:rpm/redhat/perl-subs@1.03-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.03-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"7a082b0e6a9156ba","cpes":["cpe:2.3:a:perl-vars:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl-vars:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_vars:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl_vars:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_vars:0\\:1.05-484.el9_8:*:*:*:*:*:*:*"],"name":"perl-vars","purl":"pkg:rpm/redhat/perl-vars@1.05-484.el9_8?arch=noarch&distro=rhel-9.8&epoch=0&upstream=perl-5.32.1-484.el9_8.src.rpm","type":"rpm","version":"0:1.05-484.el9_8","language":"","licenses":["GPL+ or Artistic"],"metadata":{"epoch":0,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"perl","version":"5.32.1-484.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"perl","version":"5.32.1-484.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57432","description":"A flaw was found in Perl. An integer overflow vulnerability in the `S_measure_struct` function, specifically when handling `pack` and `unpack` templates with large repeat counts, can lead to an out-of-bounds heap read. This allows an attacker, by providing a specially crafted template, to read sensitive information from memory beyond the intended buffer. This could result in the disclosure of confidential data."},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"a3c55d7a5e4bf54f","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":3.4,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.10396,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19542","description":"A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the `tdelete` function. This issue occurs due to incorrect management of array sizes, which can lead to memory corruption. A local attacker with low privileges could potentially exploit this to cause a denial of service or disclose sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":3.4,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.10396,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19542","description":"A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the `tdelete` function. This issue occurs due to incorrect management of array sizes, which can lead to memory corruption. A local attacker with low privileges could potentially exploit this to cause a denial of service or disclose sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":3.4,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.10396,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19542","description":"A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the `tdelete` function. This issue occurs due to incorrect management of array sizes, which can lead to memory corruption. A local attacker with low privileges could potentially exploit this to cause a denial of service or disclose sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"d0a796bfde79311d","cpes":["cpe:2.3:a:python-virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:virtualenv:21.5.1:*:*:*:*:*:*:*"],"name":"virtualenv","purl":"pkg:pypi/virtualenv@21.5.1","type":"python","version":"21.5.1","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"21.7.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x78j-v8h9-3j2q","versionConstraint":"<=21.7.11 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"virtualenv","version":"21.5.1"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-x78j-v8h9-3j2q","fix":{"state":"fixed","versions":["21.7.12"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"21.7.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102937","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102937","date":"2026-10-08","epss":0.0014,"percentile":0.02884}],"risk":0.1036,"urls":["https://github.com/pypa/virtualenv/security/advisories/GHSA-x78j-v8h9-3j2q","https://nvd.nist.gov/vuln/detail/CVE-2026-102937","https://github.com/pypa/virtualenv/pull/3250","https://github.com/pypa/virtualenv/commit/d721ff140ce4afdc2a9b76751e4584e25d9fbea6","https://github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4014.yaml","https://github.com/pypa/virtualenv","https://github.com/pypa/virtualenv/releases/tag/21.7.12","https://pypi.org/project/virtualenv"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x78j-v8h9-3j2q","description":"virtualenv: Command injection via --prompt in activate.bat (batch activator)"},"relatedVulnerabilities":[{"id":"CVE-2026-102937","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102937","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102937","date":"2026-10-08","epss":0.0014,"percentile":0.02884}],"urls":["https://github.com/pypa/virtualenv/commit/d721ff140ce4afdc2a9b76751e4584e25d9fbea6","https://github.com/pypa/virtualenv/pull/3250","https://github.com/pypa/virtualenv/releases/tag/21.7.12","https://github.com/pypa/virtualenv/security/advisories/GHSA-x78j-v8h9-3j2q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102937","description":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, BatchActivator.quote() returns prompt text unchanged before activate.bat inserts it into a cmd.exe set \"VAR=value\" statement. An attacker who influences --prompt, VIRTUALENV_PROMPT, or the corresponding configuration value can include a double quote that closes the assignment and leaves following cmd.exe operators as executable syntax. When a user activates the generated Windows environment, the injected commands run with that user's privileges. This issue is fixed in version 21.7.12."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56406","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56406","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56406","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56406","date":"2026-10-08","epss":0.00174,"percentile":0.06239}],"risk":0.10353000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56406","description":"A flaw was found in libexpat. An integer overflow vulnerability exists in the `XML_ParseBuffer` function due to a missing check. This flaw could allow an attacker to cause memory corruption, potentially leading to arbitrary code execution, information disclosure, or a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-56406","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56406","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56406","date":"2026-10-08","epss":0.00174,"percentile":0.06239}],"urls":["https://github.com/libexpat/libexpat/pull/1255"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56406","description":"libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56407","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56407","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56407","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56407","date":"2026-10-08","epss":0.00174,"percentile":0.06239}],"risk":0.10353000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56407","description":"An integer overflow exists in libexpat's doProlog function due to improper handling of entity value lengths. A local attacker could exploit this to execute arbitrary code or access sensitive system data."},"relatedVulnerabilities":[{"id":"CVE-2026-56407","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56407","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56407","date":"2026-10-08","epss":0.00174,"percentile":0.06239}],"urls":["https://github.com/libexpat/libexpat/pull/1262"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56407","description":"libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen."}]},{"artifact":{"id":"e1b413eca8446714","cpes":["cpe:2.3:a:libarchive:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libarchive-3.5.3-11.el9_8.src.rpm","type":"rpm","version":"3.5.3-11.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-30571","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libarchive","version":"0:3.5.3-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-30571","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-30571","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-30571","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-30571","date":"2026-10-08","epss":0.00194,"percentile":0.08302}],"risk":0.09991000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-30571","description":"A vulnerability was found in libarchive. This issue can cause a race condition in a multi-threaded use of archive_write_disk_header() on posix based systems, which could allow implicit directory creation with permissions 777, without sticky bit, which means any low privileged user on the system can delete and rename files inside those directories."},"relatedVulnerabilities":[{"id":"CVE-2023-30571","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":3.9,"impactScore":2.8,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-30571","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-30571","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-30571","date":"2026-10-08","epss":0.00194,"percentile":0.08302}],"urls":["https://github.com/libarchive/libarchive/issues/1876","https://groups.google.com/g/libarchive-announce"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-30571","description":"Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories."}]},{"artifact":{"id":"aff0baca8a045287","cpes":["cpe:2.3:a:libblkid:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libblkid","purl":"pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.09912,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"9ee075f0f02757cc","cpes":["cpe:2.3:a:libfdisk:libfdisk:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libfdisk:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libfdisk","purl":"pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.09912,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"66ba386a85828620","cpes":["cpe:2.3:a:libmount:libmount:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libmount:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libmount","purl":"pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.09912,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"0a9bd32f064c052f","cpes":["cpe:2.3:a:libsmartcols:libsmartcols:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libsmartcols:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libsmartcols","purl":"pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.09912,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"63e8f89642ab1486","cpes":["cpe:2.3:a:libuuid:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libuuid","purl":"pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.09912,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"28dc83c2657e893e","cpes":["cpe:2.3:a:util-linux:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["GPLv2 and GPLv2+ and LGPLv2+ and BSD with advertising and Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"0:2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.09912,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"97ebf56955dbe4a2","cpes":["cpe:2.3:a:util-linux-core:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-core:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_core:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_core:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"util-linux-core","purl":"pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["GPLv2 and GPLv2+ and LGPLv2+ and BSD with advertising and Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.09912,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"a3c55d7a5e4bf54f","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-97399","description":"A flaw was found in glibc. In builds optimized for specific hardware architectures, the string comparison function strncasecmp may read one byte beyond the boundary of the provided input string. An attacker capable of passing controlled strings that end at the edge of a memory page could trigger an invalid memory access and crash the application, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-97399","description":"A flaw was found in glibc. In builds optimized for specific hardware architectures, the string comparison function strncasecmp may read one byte beyond the boundary of the provided input string. An attacker capable of passing controlled strings that end at the edge of a memory page could trigger an invalid memory access and crash the application, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-97399","description":"A flaw was found in glibc. In builds optimized for specific hardware architectures, the string comparison function strncasecmp may read one byte beyond the boundary of the provided input string. An attacker capable of passing controlled strings that end at the edge of a memory page could trigger an invalid memory access and crash the application, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"152f717dbbb7ecf4","cpes":["cpe:2.3:a:coreutils-single:coreutils-single:8.32-41.el9_8.1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-single:coreutils_single:8.32-41.el9_8.1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_single:coreutils-single:8.32-41.el9_8.1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_single:coreutils_single:8.32-41.el9_8.1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-single:8.32-41.el9_8.1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_single:8.32-41.el9_8.1:*:*:*:*:*:*:*","cpe:2.3:a:redhat:coreutils-single:8.32-41.el9_8.1:*:*:*:*:*:*:*","cpe:2.3:a:redhat:coreutils_single:8.32-41.el9_8.1:*:*:*:*:*:*:*"],"name":"coreutils-single","purl":"pkg:rpm/redhat/coreutils-single@8.32-41.el9_8.1?arch=x86_64&distro=rhel-9.8&upstream=coreutils-8.32-41.el9_8.1.src.rpm","type":"rpm","version":"8.32-41.el9_8.1","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils","version":"8.32-41.el9_8.1"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56391","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"coreutils","version":"8.32-41.el9_8.1"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.09490499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56391","description":"A flaw was found in GNU coreutils uniq. When processing specially crafted multibyte input with the --check-chars option, an attacker can trigger an out-of-bounds read. This vulnerability can lead to a denial of service (DoS) due to an application crash and potentially expose sensitive information from adjacent memory."},"relatedVulnerabilities":[{"id":"CVE-2026-56391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."}]},{"artifact":{"id":"1c9a349fe96f859f","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=sqlite-3.34.1-11.el9_8.src.rpm","type":"rpm","version":"3.34.1-11.el9_8","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite","version":"3.34.1-11.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-70873","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"sqlite","version":"3.34.1-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-70873","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-70873","cwe":"CWE-244","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-70873","date":"2026-10-08","epss":0.00301,"percentile":0.20911}],"risk":0.09481499999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-70873","description":"A flaw was found in SQLite. This information disclosure vulnerability exists within the zipfile extension, specifically in the zipfileInflate function. A remote attacker could exploit this by providing a specially crafted ZIP file. Successful exploitation could lead to the disclosure of sensitive heap memory information."},"relatedVulnerabilities":[{"id":"CVE-2025-70873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-70873","cwe":"CWE-244","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-70873","date":"2026-10-08","epss":0.00301,"percentile":0.20911}],"urls":["https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054","https://sqlite.org/forum/forumpost/761eac3c82","https://sqlite.org/src/info/3d459f1fb1bd1b5e"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-70873","description":"An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.09387,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89161","description":"A flaw was found in PCRE2, a library for processing regular expressions. The `pcre2_jit_match` function, which handles just-in-time (JIT) compilation for regular expressions, incorrectly manages memory when processing certain inputs. This memory corruption vulnerability could allow a local attacker to cause the application to crash, leading to a denial of service, or potentially execute unauthorized code."},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.09387,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89161","description":"A flaw was found in PCRE2, a library for processing regular expressions. The `pcre2_jit_match` function, which handles just-in-time (JIT) compilation for regular expressions, incorrectly manages memory when processing certain inputs. This memory corruption vulnerability could allow a local attacker to cause the application to crash, leading to a denial of service, or potentially execute unauthorized code."},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"6b29b8ef2f83cc22","cpes":["cpe:2.3:a:redhat:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm","purl":"pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-95519","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"0:4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95519","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95519","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95519","date":"2026-10-08","epss":0.00144,"percentile":0.03171}],"risk":0.09216,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95519","description":"A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account."},"relatedVulnerabilities":[{"id":"CVE-2026-95519","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95519","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95519","date":"2026-10-08","epss":0.00144,"percentile":0.03171}],"urls":["https://access.redhat.com/security/cve/CVE-2026-95519","https://bugzilla.redhat.com/show_bug.cgi?id=2470977"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95519","description":"A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account."}]},{"artifact":{"id":"108e4bcd5f0cf305","cpes":["cpe:2.3:a:rpm-libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm-libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm-libs","purl":"pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.16.1.3-40.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95519","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95519","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95519","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95519","date":"2026-10-08","epss":0.00144,"percentile":0.03171}],"risk":0.09216,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95519","description":"A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account."},"relatedVulnerabilities":[{"id":"CVE-2026-95519","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95519","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95519","date":"2026-10-08","epss":0.00144,"percentile":0.03171}],"urls":["https://access.redhat.com/security/cve/CVE-2026-95519","https://bugzilla.redhat.com/show_bug.cgi?id=2470977"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95519","description":"A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account."}]},{"artifact":{"id":"e1b413eca8446714","cpes":["cpe:2.3:a:libarchive:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libarchive-3.5.3-11.el9_8.src.rpm","type":"rpm","version":"3.5.3-11.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5915","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libarchive","version":"0:3.5.3-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-5915","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":6.6,"impactScore":5.2,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5915","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5915","date":"2026-10-08","epss":0.00192,"percentile":0.0813}],"risk":0.09215999999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5915","description":"A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions."},"relatedVulnerabilities":[{"id":"CVE-2025-5915","cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":6.6,"impactScore":5.2,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H","metrics":{"baseScore":6.6,"impactScore":5.2,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5915","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5915","date":"2026-10-08","epss":0.00192,"percentile":0.0813}],"urls":["https://access.redhat.com/security/cve/CVE-2025-5915","https://bugzilla.redhat.com/show_bug.cgi?id=2370865","https://github.com/libarchive/libarchive/pull/2599","https://github.com/libarchive/libarchive/releases/tag/v3.8.0"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5915","description":"A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (denial of service), or the disclosure of sensitive information from adjacent memory regions."}]},{"artifact":{"id":"6c6ff44b2d10b255","cpes":["cpe:2.3:a:bzip2-libs:bzip2-libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:bzip2-libs:bzip2_libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:bzip2_libs:bzip2-libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:bzip2_libs:bzip2_libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:bzip2-libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:bzip2_libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:bzip2:bzip2-libs:1.0.8-11.el9:*:*:*:*:*:*:*","cpe:2.3:a:bzip2:bzip2_libs:1.0.8-11.el9:*:*:*:*:*:*:*"],"name":"bzip2-libs","purl":"pkg:rpm/redhat/bzip2-libs@1.0.8-11.el9?arch=x86_64&distro=rhel-9.8&upstream=bzip2-1.0.8-11.el9.src.rpm","type":"rpm","version":"1.0.8-11.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"bzip2","version":"1.0.8-11.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"bzip2","version":"1.0.8-11.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-42250","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42250","description":"A flaw was found in bzip2. The bzip2recover utility contains an off-by-one error that allows a local attacker to cause an out-of-bounds write to a global buffer by processing a specially crafted file. This memory corruption can lead to a crash, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-42250","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"}]},{"artifact":{"id":"e1b413eca8446714","cpes":["cpe:2.3:a:libarchive:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libarchive-3.5.3-11.el9_8.src.rpm","type":"rpm","version":"3.5.3-11.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15028","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libarchive","version":"0:3.5.3-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15028","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15028","cwe":"CWE-805","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-15028","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-15028","date":"2026-10-08","epss":0.00204,"percentile":0.09483}],"risk":0.09078,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15028","description":"A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-15028","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15028","cwe":"CWE-805","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-15028","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-15028","date":"2026-10-08","epss":0.00204,"percentile":0.09483}],"urls":["https://access.redhat.com/errata/RHSA-2026:38279","https://access.redhat.com/errata/RHSA-2026:69553","https://access.redhat.com/security/cve/CVE-2026-15028","https://bugzilla.redhat.com/show_bug.cgi?id=2497970","https://github.com/libarchive/libarchive/issues/3251","https://github.com/libarchive/libarchive/pull/3253"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15028","description":"A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system."}]},{"artifact":{"id":"e1b413eca8446714","cpes":["cpe:2.3:a:libarchive:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libarchive-3.5.3-11.el9_8.src.rpm","type":"rpm","version":"3.5.3-11.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-60753","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libarchive","version":"0:3.5.3-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-60753","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60753","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-60753","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60753","date":"2026-10-08","epss":0.00172,"percentile":0.06022}],"risk":0.0903,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-60753","description":"A vulnerability in apply_substitution() function in libarchive's bsdtar allows crafted -s substitution rules to repeatedly match a zero-length substring and append replacements without advancing the input pointer. When the rule uses the global /g flag (or an explicitly empty pattern), this leads to unbounded output allocation and eventual process OOM (Denial of Service). Upgrade to libarchive 3.8.1 or apply a patch that prevents zero-length match loops or rejects empty patterns."},"relatedVulnerabilities":[{"id":"CVE-2025-60753","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60753","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-60753","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60753","date":"2026-10-08","epss":0.00172,"percentile":0.06022}],"urls":["https://github.com/Papya-j/CVE/tree/main/CVE-2025-60753","https://github.com/libarchive/libarchive/issues/2725"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60753","description":"An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash)."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.08978,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89160","description":"A flaw was found in PCRE2, a library for processing regular expressions. A remote attacker could exploit this vulnerability by providing a specially crafted input that triggers an out-of-bounds read during pattern matching with invalid UTF (Unicode Transformation Format) characters. This could lead to a denial of service, making the affected system or application unavailable."},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.08978,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89160","description":"A flaw was found in PCRE2, a library for processing regular expressions. A remote attacker could exploit this vulnerability by providing a specially crafted input that triggers an out-of-bounds read during pattern matching with invalid UTF (Unicode Transformation Format) characters. This could lead to a denial of service, making the affected system or application unavailable."},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"e1b413eca8446714","cpes":["cpe:2.3:a:libarchive:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libarchive-3.5.3-11.el9_8.src.rpm","type":"rpm","version":"3.5.3-11.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5745","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libarchive","version":"0:3.5.3-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-5745","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5745","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5745","date":"2026-10-08","epss":0.00171,"percentile":0.0594}],"risk":0.089775,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5745","description":"A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-5745","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5745","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5745","date":"2026-10-08","epss":0.00171,"percentile":0.0594}],"urls":["https://access.redhat.com/errata/RHSA-2026:8944","https://access.redhat.com/security/cve/CVE-2026-5745","https://bugzilla.redhat.com/show_bug.cgi?id=2455921"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5745","description":"A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare \"d\" or \"default\" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS)."}]},{"artifact":{"id":"7506ae3b753c6ea1","cpes":["cpe:2.3:a:openldap:openldap:2.6.8-4.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openldap:2.6.8-4.el9:*:*:*:*:*:*:*"],"name":"openldap","purl":"pkg:rpm/redhat/openldap@2.6.8-4.el9?arch=x86_64&distro=rhel-9.8&upstream=openldap-2.6.8-4.el9.src.rpm","type":"rpm","version":"2.6.8-4.el9","language":"","licenses":["OLDAP-2.8"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-22185","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openldap","version":"0:2.6.8-4.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-22185","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-22185","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-22185","date":"2026-10-08","epss":0.00152,"percentile":0.03787}],"risk":0.08968,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-22185","description":"A flaw was found in OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load. When processing malformed input, a local attacker can exploit a heap buffer underflow vulnerability in the readline() function. This can lead to an out-of-bounds read, potentially causing a denial of service (DoS) and limited disclosure of heap memory contents."},"relatedVulnerabilities":[{"id":"CVE-2026-22185","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-22185","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-22185","date":"2026-10-08","epss":0.00152,"percentile":0.03787}],"urls":["https://bugs.openldap.org/show_bug.cgi?id=10421","https://seclists.org/fulldisclosure/2026/Jan/5","https://seclists.org/fulldisclosure/2026/Jan/8","https://www.openldap.org/","https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22185","description":"OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.089445,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-35189","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by presenting a specially crafted certificate during a Transport Layer Security (TLS) handshake. When OpenSSL processes and caches certificate extensions containing numerous Certificate Revocation List (CRL) distribution points, it allocates an excessive amount of memory. This disproportionate memory usage can exhaust system resources and crash the affected client or server application."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.089445,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-35189","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by presenting a specially crafted certificate during a Transport Layer Security (TLS) handshake. When OpenSSL processes and caches certificate extensions containing numerous Certificate Revocation List (CRL) distribution points, it allocates an excessive amount of memory. This disproportionate memory usage can exhaust system resources and crash the affected client or server application."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.089445,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-35189","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by presenting a specially crafted certificate during a Transport Layer Security (TLS) handshake. When OpenSSL processes and caches certificate extensions containing numerous Certificate Revocation List (CRL) distribution points, it allocates an excessive amount of memory. This disproportionate memory usage can exhaust system resources and crash the affected client or server application."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"e988ae274c693810","cpes":["cpe:2.3:a:redhat:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=tar-1.34-13.el9_8.src.rpm","type":"rpm","version":"2:1.34-13.el9_8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-39804","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"tar","version":"2:1.34-13.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2023-39804","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39804","date":"2026-10-08","epss":0.00283,"percentile":0.19024}],"risk":0.08914499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-39804","description":"A flaw was found in tar. This issue occurs when extended attributes are processed in PAX archives, and could allow an attacker to cause an application crash, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2023-39804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39804","date":"2026-10-08","epss":0.00283,"percentile":0.19024}],"urls":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1058079","https://git.savannah.gnu.org/cgit/tar.git/commit/?id=a339f05cd269013fa133d2f148d73f6f7d4247e4","https://git.savannah.gnu.org/cgit/tar.git/tree/src/xheader.c?h=release_1_34#n1723","https://lists.debian.org/debian-lts-announce/2024/03/msg00008.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39804","description":"In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-32776","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-32776","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32776","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32776","date":"2026-10-08","epss":0.00159,"percentile":0.04405}],"risk":0.08904000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-32776","description":"A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted XML content with empty external parameter entities. This could lead to a NULL pointer dereference, causing the application to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-32776","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32776","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32776","date":"2026-10-08","epss":0.00159,"percentile":0.04405}],"urls":["https://github.com/libexpat/libexpat/pull/1158","https://github.com/libexpat/libexpat/pull/1159","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32776","description":"libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56412","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56412","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56412","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56412","date":"2026-10-08","epss":0.00179,"percentile":0.06808}],"risk":0.088605,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56412","description":"A flaw was found in libexpat. This vulnerability, present in versions before 2.8.2, stems from improper handling of XML CDATA sections, where the library fails to adequately track the depth of handler calls. This can result in a 'use-after-free' error, a type of memory corruption that could allow an attacker to crash the application or potentially gain unauthorized control."},"relatedVulnerabilities":[{"id":"CVE-2026-56412","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.9,"impactScore":3.4,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56412","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56412","date":"2026-10-08","epss":0.00179,"percentile":0.06808}],"urls":["https://github.com/libexpat/libexpat/pull/1278"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56412","description":"libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219."}]},{"artifact":{"id":"3e12e13633c8c2ad","cpes":["cpe:2.3:a:systemd:systemd:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd:252-67.el9_8.6:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:rpm/redhat/systemd@252-67.el9_8.6?arch=x86_64&distro=rhel-9.8&upstream=systemd-252-67.el9_8.6.src.rpm","type":"rpm","version":"252-67.el9_8.6","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4105","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"systemd","version":"0:252-67.el9_8.6"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4105","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-08","epss":0.00149,"percentile":0.03546}],"risk":0.08716499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."},"relatedVulnerabilities":[{"id":"CVE-2026-4105","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-08","epss":0.00149,"percentile":0.03546}],"urls":["https://access.redhat.com/errata/RHSA-2026:7299","https://access.redhat.com/security/cve/CVE-2026-4105","https://bugzilla.redhat.com/show_bug.cgi?id=2447262","https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."}]},{"artifact":{"id":"7cc67259267c7b44","cpes":["cpe:2.3:a:systemd-libs:systemd-libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd-libs:systemd_libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd-libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd_libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_libs:252-67.el9_8.6:*:*:*:*:*:*:*"],"name":"systemd-libs","purl":"pkg:rpm/redhat/systemd-libs@252-67.el9_8.6?arch=x86_64&distro=rhel-9.8&upstream=systemd-252-67.el9_8.6.src.rpm","type":"rpm","version":"252-67.el9_8.6","language":"","licenses":["LGPLv2+ and MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"252-67.el9_8.6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4105","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"systemd","version":"252-67.el9_8.6"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4105","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-08","epss":0.00149,"percentile":0.03546}],"risk":0.08716499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."},"relatedVulnerabilities":[{"id":"CVE-2026-4105","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-08","epss":0.00149,"percentile":0.03546}],"urls":["https://access.redhat.com/errata/RHSA-2026:7299","https://access.redhat.com/security/cve/CVE-2026-4105","https://bugzilla.redhat.com/show_bug.cgi?id=2447262","https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."}]},{"artifact":{"id":"03f55f59432bdc4e","cpes":["cpe:2.3:a:systemd-pam:systemd-pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd-pam:systemd_pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_pam:systemd-pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_pam:systemd_pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_pam:252-67.el9_8.6:*:*:*:*:*:*:*"],"name":"systemd-pam","purl":"pkg:rpm/redhat/systemd-pam@252-67.el9_8.6?arch=x86_64&distro=rhel-9.8&upstream=systemd-252-67.el9_8.6.src.rpm","type":"rpm","version":"252-67.el9_8.6","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"252-67.el9_8.6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4105","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"systemd","version":"252-67.el9_8.6"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4105","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-08","epss":0.00149,"percentile":0.03546}],"risk":0.08716499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."},"relatedVulnerabilities":[{"id":"CVE-2026-4105","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-08","epss":0.00149,"percentile":0.03546}],"urls":["https://access.redhat.com/errata/RHSA-2026:7299","https://access.redhat.com/security/cve/CVE-2026-4105","https://bugzilla.redhat.com/show_bug.cgi?id=2447262","https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."}]},{"artifact":{"id":"4551ade83316fa19","cpes":["cpe:2.3:a:systemd-rpm-macros:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd-rpm-macros:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_rpm_macros:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_rpm_macros:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd-rpm:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd-rpm:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_rpm:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_rpm:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*"],"name":"systemd-rpm-macros","purl":"pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.6?arch=noarch&distro=rhel-9.8&upstream=systemd-252-67.el9_8.6.src.rpm","type":"rpm","version":"252-67.el9_8.6","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"252-67.el9_8.6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4105","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"systemd","version":"252-67.el9_8.6"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-4105","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-08","epss":0.00149,"percentile":0.03546}],"risk":0.08716499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."},"relatedVulnerabilities":[{"id":"CVE-2026-4105","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-08","epss":0.00149,"percentile":0.03546}],"urls":["https://access.redhat.com/errata/RHSA-2026:7299","https://access.redhat.com/security/cve/CVE-2026-4105","https://bugzilla.redhat.com/show_bug.cgi?id=2447262","https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."}]},{"artifact":{"id":"d4d165231b963ffc","cpes":["cpe:2.3:a:redhat:pcre2:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.40-6.el9?arch=x86_64&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"0:10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.08672999999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89156","description":"A flaw was found in PCRE2. An attacker can provide invalid UTF (Unicode Transformation Format) data, leading to an out-of-bounds read during a Just-In-Time (JIT) fallback. This vulnerability could potentially result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"5717d3536e0a895a","cpes":["cpe:2.3:a:pcre2-syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2-syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2_syntax:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2-syntax:10.40-6.el9:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2_syntax:10.40-6.el9:*:*:*:*:*:*:*"],"name":"pcre2-syntax","purl":"pkg:rpm/redhat/pcre2-syntax@10.40-6.el9?arch=noarch&distro=rhel-9.8&upstream=pcre2-10.40-6.el9.src.rpm","type":"rpm","version":"10.40-6.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2","version":"10.40-6.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pcre2","version":"10.40-6.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.08672999999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-89156","description":"A flaw was found in PCRE2. An attacker can provide invalid UTF (Unicode Transformation Format) data, leading to an out-of-bounds read during a Just-In-Time (JIT) fallback. This vulnerability could potentially result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"e988ae274c693810","cpes":["cpe:2.3:a:redhat:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=tar-1.34-13.el9_8.src.rpm","type":"rpm","version":"2:1.34-13.el9_8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53655","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"tar","version":"2:1.34-13.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53655","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53655","cwe":"CWE-436","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-53655","date":"2026-10-08","epss":0.00156,"percentile":0.04204}],"risk":0.08657999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53655","description":"A flaw was found in node-tar. This vulnerability arises because node-tar incorrectly applies PAX extended header size records to subsequent intermediary metadata headers, leading to a desynchronization of the tar stream cursor compared to other standard tar implementations. A remote attacker could exploit this by crafting a malicious archive, causing different interpretations of archive contents between node-tar and other tools. This could allow an attacker to hide malicious files or sensitive information from security scanners that rely on different tar parsing libraries, potentially leading to information disclosure or bypassing security controls."},"relatedVulnerabilities":[{"id":"CVE-2026-53655","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53655","cwe":"CWE-436","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-53655","date":"2026-10-08","epss":0.00156,"percentile":0.04204}],"urls":["https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53655","description":"node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the byte length of an intervening L/K/x header, an attacker can desynchronize node-tar's stream cursor relative to every other mainstream tar implementation (GNU tar, libarchive/bsdtar, Python tarfile, and the now-fixed tar-rs / astral-tokio-tar). The result is a tar parser interpretation differential (CWE-436): a single crafted archive yields a different set of members under node-tar than under the reference tar tools. An attacker can use this to hide a member from one parser while it is visible to another, which defeats security tooling whose scanner and extractor disagree on archive contents (e.g. a malware/secret scanner that lists entries with one library while a downstream step extracts with another) This vulnerability is fixed in 7.5.16."}]},{"artifact":{"id":"987c8daac6c0f9f4","cpes":["cpe:2.3:a:libsolv:libsolv:0.7.24-6.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libsolv:0.7.24-6.el9_8:*:*:*:*:*:*:*"],"name":"libsolv","purl":"pkg:rpm/redhat/libsolv@0.7.24-6.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libsolv-0.7.24-6.el9_8.src.rpm","type":"rpm","version":"0.7.24-6.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82327","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libsolv","version":"0:0.7.24-6.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-82327","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82327","cwe":"CWE-129","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-82327","date":"2026-10-08","epss":0.00163,"percentile":0.04973}],"risk":0.085575,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-82327","description":"A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value."},"relatedVulnerabilities":[{"id":"CVE-2026-82327","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82327","cwe":"CWE-129","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-82327","date":"2026-10-08","epss":0.00163,"percentile":0.04973}],"urls":["https://access.redhat.com/security/cve/CVE-2026-82327","https://bugzilla.redhat.com/show_bug.cgi?id=2525602"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82327","description":"A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache files. When libsolv rewrites a .solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted .solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value."}]},{"artifact":{"id":"1c9a349fe96f859f","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.34.1-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.34.1-11.el9_8:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:rpm/redhat/sqlite-libs@3.34.1-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=sqlite-3.34.1-11.el9_8.src.rpm","type":"rpm","version":"3.34.1-11.el9_8","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite","version":"3.34.1-11.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-50812","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"sqlite","version":"3.34.1-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-50812","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50812","date":"2026-10-08","epss":0.0016,"percentile":0.04607}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-50812","description":"A flaw was found in SQLite. The Session Extension in SQLite is vulnerable to a NULL pointer dereference. A remote attacker could exploit this by supplying a specially crafted, malformed changeset blob. This could lead to a denial of service, making the application unavailable to legitimate users."},"relatedVulnerabilities":[{"id":"CVE-2026-50812","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50812","date":"2026-10-08","epss":0.0016,"percentile":0.04607}],"urls":["https://gist.github.com/junius-sec/bb556f333957c5226dede314db0e9e91","https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d","https://sqlite.org/src/info/e807d4e3798efd53"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50812","description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer."}]},{"artifact":{"id":"3e12e13633c8c2ad","cpes":["cpe:2.3:a:systemd:systemd:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd:252-67.el9_8.6:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:rpm/redhat/systemd@252-67.el9_8.6?arch=x86_64&distro=rhel-9.8&upstream=systemd-252-67.el9_8.6.src.rpm","type":"rpm","version":"252-67.el9_8.6","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"systemd","version":"0:252-67.el9_8.6"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15059","description":"A flaw was found in systemd-oomd. Local unprivileged users can exploit a missing path traversal validation in the systemd-oomd Inter-Process Communication (IPC) Application Programming Interface (API). This vulnerability allows them to terminate arbitrary local processes, leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"7cc67259267c7b44","cpes":["cpe:2.3:a:systemd-libs:systemd-libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd-libs:systemd_libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd-libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd_libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-libs:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_libs:252-67.el9_8.6:*:*:*:*:*:*:*"],"name":"systemd-libs","purl":"pkg:rpm/redhat/systemd-libs@252-67.el9_8.6?arch=x86_64&distro=rhel-9.8&upstream=systemd-252-67.el9_8.6.src.rpm","type":"rpm","version":"252-67.el9_8.6","language":"","licenses":["LGPLv2+ and MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"252-67.el9_8.6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"systemd","version":"252-67.el9_8.6"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15059","description":"A flaw was found in systemd-oomd. Local unprivileged users can exploit a missing path traversal validation in the systemd-oomd Inter-Process Communication (IPC) Application Programming Interface (API). This vulnerability allows them to terminate arbitrary local processes, leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"03f55f59432bdc4e","cpes":["cpe:2.3:a:systemd-pam:systemd-pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd-pam:systemd_pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_pam:systemd-pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_pam:systemd_pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-pam:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_pam:252-67.el9_8.6:*:*:*:*:*:*:*"],"name":"systemd-pam","purl":"pkg:rpm/redhat/systemd-pam@252-67.el9_8.6?arch=x86_64&distro=rhel-9.8&upstream=systemd-252-67.el9_8.6.src.rpm","type":"rpm","version":"252-67.el9_8.6","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"252-67.el9_8.6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"systemd","version":"252-67.el9_8.6"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15059","description":"A flaw was found in systemd-oomd. Local unprivileged users can exploit a missing path traversal validation in the systemd-oomd Inter-Process Communication (IPC) Application Programming Interface (API). This vulnerability allows them to terminate arbitrary local processes, leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"4551ade83316fa19","cpes":["cpe:2.3:a:systemd-rpm-macros:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd-rpm-macros:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_rpm_macros:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_rpm_macros:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd-rpm:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd-rpm:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_rpm:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd_rpm:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-rpm-macros:252-67.el9_8.6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_rpm_macros:252-67.el9_8.6:*:*:*:*:*:*:*"],"name":"systemd-rpm-macros","purl":"pkg:rpm/redhat/systemd-rpm-macros@252-67.el9_8.6?arch=noarch&distro=rhel-9.8&upstream=systemd-252-67.el9_8.6.src.rpm","type":"rpm","version":"252-67.el9_8.6","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"252-67.el9_8.6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"systemd","version":"252-67.el9_8.6"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15059","description":"A flaw was found in systemd-oomd. Local unprivileged users can exploit a missing path traversal validation in the systemd-oomd Inter-Process Communication (IPC) Application Programming Interface (API). This vulnerability allows them to terminate arbitrary local processes, leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56131","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56131","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.5,"impactScore":3.4,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56131","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56131","date":"2026-10-08","epss":0.00175,"percentile":0.06422}],"risk":0.08312499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56131","description":"A use-after-free vulnerability in libexpat occurs because handler call depth isn't properly tracked when XML_ResumeParser is invoked during policy violations. This flaw can lead to information disclosure, data corruption, or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-56131","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56131","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56131","date":"2026-10-08","epss":0.00175,"percentile":0.06422}],"urls":["https://github.com/libexpat/libexpat/pull/1267"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56131","description":"libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation)."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-32778","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-32778","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.1,"impactScore":3.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32778","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32778","date":"2026-10-08","epss":0.00157,"percentile":0.04243}],"risk":0.079285,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-32778","description":"A flaw was found in libexpat. This vulnerability allows an attacker to trigger a NULL pointer dereference in the `setContext` function. This occurs when the system attempts to retry an operation after an out-of-memory condition, which can lead to a Denial of Service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-32778","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32778","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32778","date":"2026-10-08","epss":0.00157,"percentile":0.04243}],"urls":["https://github.com/libexpat/libexpat/pull/1159","https://github.com/libexpat/libexpat/pull/1163","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32778","description":"libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-32777","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-32777","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32777","date":"2026-10-08","epss":0.00174,"percentile":0.06263}],"risk":0.07830000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-32777","description":"A flaw was found in libexpat. A remote attacker could exploit this vulnerability by providing specially crafted Document Type Definition (DTD) content. This could lead to an infinite loop during parsing, resulting in a Denial of Service (DoS) for the application using libexpat."},"relatedVulnerabilities":[{"id":"CVE-2026-32777","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32777","cwe":"CWE-835","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-32777","date":"2026-10-08","epss":0.00174,"percentile":0.06263}],"urls":["https://github.com/libexpat/libexpat/issues/1161","https://github.com/libexpat/libexpat/pull/1159","https://github.com/libexpat/libexpat/pull/1162","https://issues.oss-fuzz.com/issues/486993411","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32777","description":"libexpat before 2.7.5 allows an infinite loop while parsing DTD content."}]},{"artifact":{"id":"dc6d4d4f15a91aef","cpes":["cpe:2.3:a:openssl:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:rpm/redhat/openssl@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"1:3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.07772,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75803","description":"A flaw in OpenSSL causes EVP_Cipher() to skip AEAD tag verification for ChaCha20-Poly1305 and AES-OCB ciphers when decrypting empty ciphertexts. This allows remote attackers to submit forged messages that affected applications incorrectly accept as valid."},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"0ffb780ff8db44ef","cpes":["cpe:2.3:a:openssl-devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_devel:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_devel:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-devel","purl":"pkg:rpm/redhat/openssl-devel@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.07772,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75803","description":"A flaw in OpenSSL causes EVP_Cipher() to skip AEAD tag verification for ChaCha20-Poly1305 and AES-OCB ciphers when decrypting empty ciphertexts. This allows remote attackers to submit forged messages that affected applications incorrectly accept as valid."},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"753337be7fe19d16","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:3.5.8-1.el9_8:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@3.5.8-1.el9_8?arch=x86_64&distro=rhel-9.8&epoch=1&upstream=openssl-3.5.8-1.el9_8.src.rpm","type":"rpm","version":"1:3.5.8-1.el9_8","language":"","licenses":["Apache-2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"3.5.8-1.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"openssl","version":"3.5.8-1.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.07772,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75803","description":"A flaw in OpenSSL causes EVP_Cipher() to skip AEAD tag verification for ChaCha20-Poly1305 and AES-OCB ciphers when decrypting empty ciphertexts. This allows remote attackers to submit forged messages that affected applications incorrectly accept as valid."},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"58e822e367013732","cpes":["cpe:2.3:a:redhat:sed:4.8-10.el9:*:*:*:*:*:*:*","cpe:2.3:a:sed:sed:4.8-10.el9:*:*:*:*:*:*:*"],"name":"sed","purl":"pkg:rpm/redhat/sed@4.8-10.el9?arch=x86_64&distro=rhel-9.8&upstream=sed-4.8-10.el9.src.rpm","type":"rpm","version":"4.8-10.el9","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5958","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"sed","version":"0:4.8-10.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-5958","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5958","cwe":"CWE-367","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-5958","date":"2026-10-08","epss":0.00137,"percentile":0.02701}],"risk":0.07740499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5958","description":"A Time-of-Check Time-of-Use (TOCTOU) race condition was found in GNU sed. When the -i (in-place) and --follow-symlinks options are used together, sed resolves the symlink but reopens the path for writing. An attacker with write access to the directory containing the symlink can swap it between the check and the open operations. If a privileged user executes sed in this manner on a path influenced by the attacker, it can lead to arbitrary file overwrites and potential privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-5958","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5958","cwe":"CWE-367","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-5958","date":"2026-10-08","epss":0.00137,"percentile":0.02701}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-5958","https://www.gnu.org/software/sed/","http://www.openwall.com/lists/oss-security/2026/05/13/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5958","description":"When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores the resolved path for determining when output is written,\n2. opens the original symlink path (not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1. This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\n\n\nThis issue was fixed in version 4.10."}]},{"artifact":{"id":"a3c55d7a5e4bf54f","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0774,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95818","description":"A flaw was found in glibc, the GNU C Library. A local attacker can exploit a stack-based buffer overflow in the dynamic loader (ld.so) when a setuid/setgid (AT_SECURE) program's DT_RPATH or DT_RUNPATH begins with $ORIGIN followed by a null character or a slash. This vulnerability allows the attacker to crash the loader, leading to a denial of service, and potentially disclose limited process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0774,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95818","description":"A flaw was found in glibc, the GNU C Library. A local attacker can exploit a stack-based buffer overflow in the dynamic loader (ld.so) when a setuid/setgid (AT_SECURE) program's DT_RPATH or DT_RUNPATH begins with $ORIGIN followed by a null character or a slash. This vulnerability allows the attacker to crash the loader, leading to a denial of service, and potentially disclose limited process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0774,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95818","description":"A flaw was found in glibc, the GNU C Library. A local attacker can exploit a stack-based buffer overflow in the dynamic loader (ld.so) when a setuid/setgid (AT_SECURE) program's DT_RPATH or DT_RUNPATH begins with $ORIGIN followed by a null character or a slash. This vulnerability allows the attacker to crash the loader, leading to a denial of service, and potentially disclose limited process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56404","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56404","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56404","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56404","date":"2026-10-08","epss":0.0013,"percentile":0.02244}],"risk":0.07734999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56404","description":"A flaw was found in libexpat. This vulnerability, an integer overflow in the `addBinding` function, could allow a local attacker to execute arbitrary code. By exploiting this, an attacker could gain control over the affected system, compromising its confidentiality and integrity."},"relatedVulnerabilities":[{"id":"CVE-2026-56404","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56404","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56404","date":"2026-10-08","epss":0.0013,"percentile":0.02244}],"urls":["https://github.com/libexpat/libexpat/pull/1249"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56404","description":"libexpat before 2.8.2 has an integer overflow in addBinding."}]},{"artifact":{"id":"6b29b8ef2f83cc22","cpes":["cpe:2.3:a:redhat:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm","purl":"pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-44605","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"0:4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-44605","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44605","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-44605","date":"2026-10-08","epss":0.00178,"percentile":0.06785}],"risk":0.07565,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-44605","description":"A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable."},"relatedVulnerabilities":[{"id":"CVE-2026-44605","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44605","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-44605","date":"2026-10-08","epss":0.00178,"percentile":0.06785}],"urls":["https://access.redhat.com/errata/RHSA-2026:33507","https://access.redhat.com/security/cve/CVE-2026-44605","https://bugzilla.redhat.com/show_bug.cgi?id=2482481"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44605","description":"A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"108e4bcd5f0cf305","cpes":["cpe:2.3:a:rpm-libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm-libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm-libs","purl":"pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.16.1.3-40.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44605","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-44605","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44605","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-44605","date":"2026-10-08","epss":0.00178,"percentile":0.06785}],"risk":0.07565,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-44605","description":"A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable."},"relatedVulnerabilities":[{"id":"CVE-2026-44605","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44605","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-44605","date":"2026-10-08","epss":0.00178,"percentile":0.06785}],"urls":["https://access.redhat.com/errata/RHSA-2026:33507","https://access.redhat.com/security/cve/CVE-2026-44605","https://bugzilla.redhat.com/show_bug.cgi?id=2482481"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44605","description":"A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading to an incorrect memory allocation. An attacker could leverage this to cause a denial of service, making the system unavailable."}]},{"artifact":{"id":"d0a796bfde79311d","cpes":["cpe:2.3:a:python-virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python-virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python_virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python-virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python_virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:virtualenv:virtualenv:21.5.1:*:*:*:*:*:*:*","cpe:2.3:a:python:virtualenv:21.5.1:*:*:*:*:*:*:*"],"name":"virtualenv","purl":"pkg:pypi/virtualenv@21.5.1","type":"python","version":"21.5.1","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/virtualenv-21.5.1.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"21.7.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9h9j-4vrj-gf7g","versionConstraint":"<=21.7.10 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"virtualenv","version":"21.5.1"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-9h9j-4vrj-gf7g","fix":{"state":"fixed","versions":["21.7.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"21.7.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":5.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102938","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102938","date":"2026-10-08","epss":0.0014,"percentile":0.02884}],"risk":0.0756,"urls":["https://github.com/pypa/virtualenv/security/advisories/GHSA-9h9j-4vrj-gf7g","https://nvd.nist.gov/vuln/detail/CVE-2026-102938","https://github.com/pypa/virtualenv/pull/3247","https://github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140","https://github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2026-4012.yaml","https://github.com/pypa/virtualenv/releases/tag/21.7.11","https://pypi.org/project/virtualenv"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9h9j-4vrj-gf7g","description":"virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection"},"relatedVulnerabilities":[{"id":"CVE-2026-102938","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102938","cwe":"CWE-93","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102938","date":"2026-10-08","epss":0.0014,"percentile":0.02884}],"urls":["https://github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140","https://github.com/pypa/virtualenv/pull/3247","https://github.com/pypa/virtualenv/releases/tag/21.7.11","https://github.com/pypa/virtualenv/security/advisories/GHSA-9h9j-4vrj-gf7g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102938","description":"virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.11, PyEnvCfg.write() writes prompt values verbatim to the line-oriented pyvenv.cfg format while PyEnvCfg._read_values() parses the file with str.splitlines() and accepts the last value for duplicate keys. An attacker who influences --prompt, VIRTUALENV_PROMPT, or configuration input can insert a recognized line boundary and additional keys, including home, causing consumers to use an attacker-selected base interpreter or corrupted environment metadata. The security impact requires prompt input from outside the operator's trust boundary; directly supplied prompt content primarily corrupts the operator's own environment. This issue is fixed in version 21.7.11."}]},{"artifact":{"id":"a3c55d7a5e4bf54f","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.0744,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86805","description":"A flaw was found in glibc, specifically within its dynamic loader (ld.so). A local attacker can exploit a time-of-check to time-of-use (TOCTOU) race condition to escalate privileges and execute arbitrary code. This occurs when the dynamic loader expands $ORIGIN in DT_RPATH for setuid/setgid programs, validating a normalized path but then opening an un-normalized path. By hard-linking such a program and winning a race to swap a path component with a symbolic link, an attacker can direct the loader to an attacker-controlled shared object, gaining elevated privileges. This vulnerability is mitigated on systems with fs.protected_hardlinks enabled."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.0744,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86805","description":"A flaw was found in glibc, specifically within its dynamic loader (ld.so). A local attacker can exploit a time-of-check to time-of-use (TOCTOU) race condition to escalate privileges and execute arbitrary code. This occurs when the dynamic loader expands $ORIGIN in DT_RPATH for setuid/setgid programs, validating a normalized path but then opening an un-normalized path. By hard-linking such a program and winning a race to swap a path component with a symbolic link, an attacker can direct the loader to an attacker-controlled shared object, gaining elevated privileges. This vulnerability is mitigated on systems with fs.protected_hardlinks enabled."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.0744,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86805","description":"A flaw was found in glibc, specifically within its dynamic loader (ld.so). A local attacker can exploit a time-of-check to time-of-use (TOCTOU) race condition to escalate privileges and execute arbitrary code. This occurs when the dynamic loader expands $ORIGIN in DT_RPATH for setuid/setgid programs, validating a normalized path but then opening an un-normalized path. By hard-linking such a program and winning a race to swap a path component with a symbolic link, an attacker can direct the loader to an attacker-controlled shared object, gaining elevated privileges. This vulnerability is mitigated on systems with fs.protected_hardlinks enabled."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"7df4fc0e81ada7f4","cpes":["cpe:2.3:a:policycoreutils:policycoreutils:3.6-5.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:policycoreutils:3.6-5.el9:*:*:*:*:*:*:*"],"name":"policycoreutils","purl":"pkg:rpm/redhat/policycoreutils@3.6-5.el9?arch=x86_64&distro=rhel-9.8&upstream=policycoreutils-3.6-5.el9.src.rpm","type":"rpm","version":"3.6-5.el9","language":"","licenses":["GPL-2.0-or-later"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59677","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"policycoreutils","version":"0:3.6-5.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-59677","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59677","cwe":"CWE-862","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-59677","date":"2026-10-08","epss":0.0014,"percentile":0.02852}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-59677","description":"A flaw was found in policycoreutils through 3.10 in seunshares. Missing authorization lets a local user in an unconfined SELinux context terminate other processes that are also unconfined, including root-owned ones. That can cause denial of service by killing critical processes."},"relatedVulnerabilities":[{"id":"CVE-2026-59677","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59677","cwe":"CWE-862","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-59677","date":"2026-10-08","epss":0.0014,"percentile":0.02852}],"urls":["https://bugzilla.suse.com/show_bug.cgi?id=1268256","https://security.opensuse.org/2026/07/15/selinux-seunshare.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59677","description":"A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in\nunconfined context\n\n\n\n\n\n\nThis issue affects policycoreutils through 3.10."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86469","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-86469","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-86469","date":"2026-10-08","epss":0.00141,"percentile":0.02941}],"risk":0.07261500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86469","description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file."},"relatedVulnerabilities":[{"id":"CVE-2026-86469","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-86469","date":"2026-10-08","epss":0.00141,"percentile":0.02941}],"urls":["https://access.redhat.com/security/cve/CVE-2026-86469","https://bugzilla.redhat.com/show_bug.cgi?id=2473839","https://gitlab.gnome.org/GNOME/glib/-/blob/main/gio/glocalfileoutputstream.c","https://gitlab.gnome.org/GNOME/glib/-/work_items/4044"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86469","description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file."}]},{"artifact":{"id":"6b29b8ef2f83cc22","cpes":["cpe:2.3:a:redhat:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm","purl":"pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103242","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"0:4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-103242","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103242","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-103242","date":"2026-10-08","epss":0.00119,"percentile":0.01634}],"risk":0.071995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-103242","description":"A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package."},"relatedVulnerabilities":[{"id":"CVE-2026-103242","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103242","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-103242","date":"2026-10-08","epss":0.00119,"percentile":0.01634}],"urls":["https://access.redhat.com/security/cve/CVE-2026-103242","https://bugzilla.redhat.com/show_bug.cgi?id=2543866"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103242","description":"A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package."}]},{"artifact":{"id":"6b29b8ef2f83cc22","cpes":["cpe:2.3:a:redhat:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm","purl":"pkg:rpm/redhat/rpm@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-95520","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"0:4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95520","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95520","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95520","date":"2026-10-08","epss":0.00119,"percentile":0.01634}],"risk":0.071995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95520","description":"A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an  untrusted package."},"relatedVulnerabilities":[{"id":"CVE-2026-95520","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95520","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95520","date":"2026-10-08","epss":0.00119,"percentile":0.01634}],"urls":["https://access.redhat.com/security/cve/CVE-2026-95520","https://bugzilla.redhat.com/show_bug.cgi?id=2537809"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95520","description":"A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an  untrusted package."}]},{"artifact":{"id":"108e4bcd5f0cf305","cpes":["cpe:2.3:a:rpm-libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm-libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm-libs","purl":"pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.16.1.3-40.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103242","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-103242","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103242","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-103242","date":"2026-10-08","epss":0.00119,"percentile":0.01634}],"risk":0.071995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-103242","description":"A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package."},"relatedVulnerabilities":[{"id":"CVE-2026-103242","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103242","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-103242","date":"2026-10-08","epss":0.00119,"percentile":0.01634}],"urls":["https://access.redhat.com/security/cve/CVE-2026-103242","https://bugzilla.redhat.com/show_bug.cgi?id=2543866"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103242","description":"A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, causing hex2binv() to allocate a one-byte buffer and then write the tag's attacker-controlled, hex-decoded content — of attacker-chosen length — past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package."}]},{"artifact":{"id":"108e4bcd5f0cf305","cpes":["cpe:2.3:a:rpm-libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm-libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-libs:4.16.1.3-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_libs:4.16.1.3-40.el9:*:*:*:*:*:*:*"],"name":"rpm-libs","purl":"pkg:rpm/redhat/rpm-libs@4.16.1.3-40.el9?arch=x86_64&distro=rhel-9.8&upstream=rpm-4.16.1.3-40.el9.src.rpm","type":"rpm","version":"4.16.1.3-40.el9","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.16.1.3-40.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95520","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"rpm","version":"4.16.1.3-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-95520","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95520","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95520","date":"2026-10-08","epss":0.00119,"percentile":0.01634}],"risk":0.071995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95520","description":"A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an  untrusted package."},"relatedVulnerabilities":[{"id":"CVE-2026-95520","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95520","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95520","date":"2026-10-08","epss":0.00119,"percentile":0.01634}],"urls":["https://access.redhat.com/security/cve/CVE-2026-95520","https://bugzilla.redhat.com/show_bug.cgi?id=2537809"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95520","description":"A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an  untrusted package."}]},{"artifact":{"id":"a3c55d7a5e4bf54f","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18374","description":"A flaw was found in the GNU C Library (glibc). This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the `fopen` function handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18374","description":"A flaw was found in the GNU C Library (glibc). This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the `fopen` function handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18374","description":"A flaw was found in the GNU C Library (glibc). This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the `fopen` function handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"5609a8ebd2e4a2c5","cpes":["cpe:2.3:a:redhat:pam:1.5.1-28.el9_8.1:*:*:*:*:*:*:*","cpe:2.3:a:pam:pam:1.5.1-28.el9_8.1:*:*:*:*:*:*:*"],"name":"pam","purl":"pkg:rpm/redhat/pam@1.5.1-28.el9_8.1?arch=x86_64&distro=rhel-9.8&upstream=pam-1.5.1-28.el9_8.1.src.rpm","type":"rpm","version":"1.5.1-28.el9_8.1","language":"","licenses":["BSD and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12610","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"pam","version":"0:1.5.1-28.el9_8.1"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-12610","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12610","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-12610","date":"2026-10-08","epss":0.00121,"percentile":0.01745}],"risk":0.06897,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-12610","description":"A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit."},"relatedVulnerabilities":[{"id":"CVE-2026-12610","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12610","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-12610","date":"2026-10-08","epss":0.00121,"percentile":0.01745}],"urls":["https://access.redhat.com/security/cve/CVE-2026-12610","https://bugzilla.redhat.com/show_bug.cgi?id=2490288","https://github.com/SSSD/sssd/issues/8796"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12610","description":"A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for privilege escalation, although it is difficult to exploit."}]},{"artifact":{"id":"e988ae274c693810","cpes":["cpe:2.3:a:redhat:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.34-13.el9_8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.34-13.el9_8?arch=x86_64&distro=rhel-9.8&epoch=2&upstream=tar-1.34-13.el9_8.src.rpm","type":"rpm","version":"2:1.34-13.el9_8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-64118","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"tar","version":"2:1.34-13.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-64118","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64118","cwe":"CWE-362","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-64118","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64118","date":"2026-10-08","epss":0.00134,"percentile":0.02517}],"risk":0.06499,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-64118","description":"A flaw was found in node-tar, a Tar utility for Node.js. This vulnerability allows a local attacker to potentially disclose sensitive information. When the .t (or .list) function is used with { sync: true } to read tar entry contents, and the tar file is concurrently modified on disk to a smaller size, the function may return uninitialized memory contents. This could lead to the exposure of arbitrary data."},"relatedVulnerabilities":[{"id":"CVE-2025-64118","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64118","cwe":"CWE-362","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-64118","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64118","date":"2026-10-08","epss":0.00134,"percentile":0.02517}],"urls":["https://github.com/isaacs/node-tar/commit/5330eb04bc43014f216e5c271b40d5c00d45224d","https://github.com/isaacs/node-tar/issues/445","https://github.com/isaacs/node-tar/pull/446","https://github.com/isaacs/node-tar/security/advisories/GHSA-29xp-372q-xqph"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-64118","description":"node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2."}]},{"artifact":{"id":"e1b413eca8446714","cpes":["cpe:2.3:a:libarchive:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libarchive-3.5.3-11.el9_8.src.rpm","type":"rpm","version":"3.5.3-11.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5916","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libarchive","version":"0:3.5.3-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-5916","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5916","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5916","date":"2026-10-08","epss":0.00185,"percentile":0.07402}],"risk":0.06382499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5916","description":"A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0."},"relatedVulnerabilities":[{"id":"CVE-2025-5916","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.6,"impactScore":4.3,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5916","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5916","date":"2026-10-08","epss":0.00185,"percentile":0.07402}],"urls":["https://access.redhat.com/security/cve/CVE-2025-5916","https://bugzilla.redhat.com/show_bug.cgi?id=2370872","https://github.com/libarchive/libarchive/pull/2568","https://github.com/libarchive/libarchive/releases/tag/v3.8.0"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5916","description":"A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior, memory corruption, or a denial-of-service condition within applications that process such archives using libarchive. This bug affects libarchive versions prior to 3.8.0."}]},{"artifact":{"id":"e1b413eca8446714","cpes":["cpe:2.3:a:libarchive:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.5.3-11.el9_8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.5.3-11.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libarchive-3.5.3-11.el9_8.src.rpm","type":"rpm","version":"3.5.3-11.el9_8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5917","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libarchive","version":"0:3.5.3-11.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-5917","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.8,"impactScore":1.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5917","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5917","date":"2026-10-08","epss":0.00214,"percentile":0.10703}],"risk":0.06205999999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5917","description":"A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0."},"relatedVulnerabilities":[{"id":"CVE-2025-5917","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.8,"impactScore":1.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5917","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5917","date":"2026-10-08","epss":0.00214,"percentile":0.10703}],"urls":["https://access.redhat.com/security/cve/CVE-2025-5917","https://bugzilla.redhat.com/show_bug.cgi?id=2370874","https://github.com/libarchive/libarchive/pull/2588","https://github.com/libarchive/libarchive/releases/tag/v3.8.0"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5917","description":"A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation. This bug affects libarchive versions prior to 3.8.0."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56405","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-56405","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56405","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56405","date":"2026-10-08","epss":0.00125,"percentile":0.0192}],"risk":0.061875000000000006,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-56405","description":"A flaw was found in libexpat. An integer overflow vulnerability exists within the `getAttributeId` function. This flaw could allow an attacker to potentially disclose sensitive information or execute arbitrary code, leading to a compromise of the system's integrity and confidentiality."},"relatedVulnerabilities":[{"id":"CVE-2026-56405","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56405","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-56405","date":"2026-10-08","epss":0.00125,"percentile":0.0192}],"urls":["https://github.com/libexpat/libexpat/pull/1251"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56405","description":"libexpat before 2.8.2 has an integer overflow in getAttributeId."}]},{"artifact":{"id":"965c5108ab84fcf4","cpes":["cpe:2.3:a:gnupg2:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*"],"name":"gnupg2","purl":"pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=rhel-9.8&upstream=gnupg2-2.3.3-5.el9_7.src.rpm","type":"rpm","version":"2.3.3-5.el9_7","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-68972","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnupg2","version":"0:2.3.3-5.el9_7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-68972","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-68972","date":"2026-10-08","epss":0.00113,"percentile":0.01342}],"risk":0.061585,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-68972","description":"A flaw was found in GnuPG. An adversary can exploit this vulnerability by crafting a signed message that includes a form feed character (\\f) at the end of a plaintext line. This allows the adversary to append additional, unsigned text to the message while the signature verification still reports success. This issue leads to an integrity bypass, potentially enabling the spoofing of signed communications."},"relatedVulnerabilities":[{"id":"CVE-2025-68972","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68972","cwe":"CWE-347","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-68972","date":"2026-10-08","epss":0.00113,"percentile":0.01342}],"urls":["https://gpg.fail/formfeed","https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i","https://news.ycombinator.com/item?id=46404339"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68972","description":"In GnuPG through 2.4.8, if a signed message has \\f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an \"invalid armor\" message is printed during verification). This is related to use of \\f as a marker to denote truncation of a long plaintext line."}]},{"artifact":{"id":"3b95a370d9cbeb72","cpes":["cpe:2.3:a:redhat:zlib:1.2.11-40.el9:*:*:*:*:*:*:*","cpe:2.3:a:zlib:zlib:1.2.11-40.el9:*:*:*:*:*:*:*"],"name":"zlib","purl":"pkg:rpm/redhat/zlib@1.2.11-40.el9?arch=x86_64&distro=rhel-9.8&upstream=zlib-1.2.11-40.el9.src.rpm","type":"rpm","version":"1.2.11-40.el9","language":"","licenses":["zlib and Boost"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"zlib","version":"0:1.2.11-40.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27171","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"risk":0.06016499999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27171","description":"A flaw was found in zlib. An attacker providing specially crafted input to the `crc32_combine64` or `crc32_combine_gen64` functions could trigger an infinite loop within the `x2nmodp` function. This leads to excessive CPU consumption, which can result in a Denial of Service (DoS) for the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-27171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"risk":0.05988500000000001,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-66382","description":"A flaw was found in libexpat. This vulnerability allows a denial of service (DoS) by processing a crafted file with an approximate size of 2 MiB, leading to dozens of seconds of processing time."},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"aff0baca8a045287","cpes":["cpe:2.3:a:libblkid:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libblkid","purl":"pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27456","description":"A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"9ee075f0f02757cc","cpes":["cpe:2.3:a:libfdisk:libfdisk:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libfdisk:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libfdisk","purl":"pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27456","description":"A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"66ba386a85828620","cpes":["cpe:2.3:a:libmount:libmount:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libmount:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libmount","purl":"pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27456","description":"A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"0a9bd32f064c052f","cpes":["cpe:2.3:a:libsmartcols:libsmartcols:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libsmartcols:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libsmartcols","purl":"pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27456","description":"A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"63e8f89642ab1486","cpes":["cpe:2.3:a:libuuid:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libuuid","purl":"pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27456","description":"A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"28dc83c2657e893e","cpes":["cpe:2.3:a:util-linux:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["GPLv2 and GPLv2+ and LGPLv2+ and BSD with advertising and Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"0:2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27456","description":"A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"97ebf56955dbe4a2","cpes":["cpe:2.3:a:util-linux-core:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-core:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_core:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_core:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"util-linux-core","purl":"pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["GPLv2 and GPLv2+ and LGPLv2+ and BSD with advertising and Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.057229999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27456","description":"A flaw was found in util-linux. When an /etc/fstab entry is configured with the user,loop options, the `mount` program checks the file path with user permissions but later opens it with root privileges. This creates a brief Time-of-Check-Time-of-Use (TOCTOU) window where an attacker can substitute the intended file with a malicious symbolic link. This allows a local unprivileged user to mount any root-owned file or block device that contains a valid filesystem, gaining full read access to its contents."},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"38f70d6bae6b19d1","cpes":["cpe:2.3:a:libgcrypt:libgcrypt:1.10.0-13.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcrypt:1.10.0-13.el9_8:*:*:*:*:*:*:*"],"name":"libgcrypt","purl":"pkg:rpm/redhat/libgcrypt@1.10.0-13.el9_8?arch=x86_64&distro=rhel-9.8&upstream=libgcrypt-1.10.0-13.el9_8.src.rpm","type":"rpm","version":"1.10.0-13.el9_8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41990","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"libgcrypt","version":"0:1.10.0-13.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-41990","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.3,"impactScore":2.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41990","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41990","date":"2026-10-08","epss":0.0018,"percentile":0.06954}],"risk":0.05669999999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-41990","description":"A flaw was found in Libgcrypt. During Dilithium signing operations, the library fails to perform a bounds check when writing to a static array. While the data involved is not directly controlled by an attacker, this vulnerability could lead to memory corruption, potentially resulting in a denial of service (DoS) or affecting data integrity."},"relatedVulnerabilities":[{"id":"CVE-2026-41990","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4,"impactScore":2.6,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41990","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41990","date":"2026-10-08","epss":0.0018,"percentile":0.06954}],"urls":["https://dev.gnupg.org/T8208","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html","https://www.openwall.com/lists/oss-security/2026/04/21/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41990","description":"Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data."}]},{"artifact":{"id":"a3c55d7a5e4bf54f","cpes":["cpe:2.3:a:redhat:glibc:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"0:2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.056174999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6368","description":"A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"88cf218ecaac1f25","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.056174999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6368","description":"A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"20293a554663f535","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.34-275.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.34-275.el9_8:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.34-275.el9_8?arch=x86_64&distro=rhel-9.8&upstream=glibc-2.34-275.el9_8.src.rpm","type":"rpm","version":"2.34-275.el9_8","language":"","licenses":["LGPL-2.1-or-later AND SunPro AND LGPL-2.1-or-later WITH GCC-exception-2.0 AND BSD-3-Clause AND GPL-2.0-or-later AND LGPL-2.1-or-later WITH GNU-compiler-exception AND GPL-2.0-only AND ISC AND LicenseRef-Fedora-Public-Domain AND HPND AND CMU-Mach AND LGPL-2.0-or-later AND Unicode-3.0 AND GFDL-1.1-or-later AND GPL-1.0-or-later AND FSFUL AND MIT AND Inner-Net-2.0 AND X11 AND GPL-2.0-or-later WITH GCC-exception-2.0 AND GFDL-1.3-only AND GFDL-1.1-only AND GPL-3.0-or-later AND GPL-3.0-or-later WITH Autoconf-exception-generic-3.0 AND GPL-3.0-or-later WITH Texinfo-exception"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.34-275.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.34-283.el9_8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"< 0:2.34-283.el9_8 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glibc","version":"2.34-275.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"fixed","versions":["0:2.34-283.el9_8"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"0:2.34-283.el9_8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.056174999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[{"id":"RHSA-2026:79281","link":"https://access.redhat.com/errata/RHSA-2026:79281"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6368","description":"A flaw was found in glibc (GNU C Library). A local attacker or application using the wordexp function with the WRDE_APPEND flag can trigger the interface to return invalid memory in the we_wordv member. This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"9eebaea2eda844dd","cpes":["cpe:2.3:a:curl-minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl-minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl_minimal:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"curl-minimal","purl":"pkg:rpm/redhat/curl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14017","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-14017","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14017","cwe":"CWE-567","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14017","date":"2026-10-08","epss":0.00114,"percentile":0.01374}],"risk":0.05585999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-14017","description":"A flaw was found in curl. When performing multi-threaded LDAPS (Lightweight Directory Access Protocol Secure) transfers, changes to Transport Layer Security (TLS) options in one thread could inadvertently apply globally, affecting other concurrent transfers. This could lead to unintended security posture changes, such as disabling certificate verification for other threads. This vulnerability can result in a security bypass, where expected security checks are not performed."},"relatedVulnerabilities":[{"id":"CVE-2025-14017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14017","cwe":"CWE-567","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14017","date":"2026-10-08","epss":0.00114,"percentile":0.01374}],"urls":["https://curl.se/docs/CVE-2025-14017.html","https://curl.se/docs/CVE-2025-14017.json","http://www.openwall.com/lists/oss-security/2026/01/07/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14017","description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well."}]},{"artifact":{"id":"b685606a6baf0f79","cpes":["cpe:2.3:a:libcurl-minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl-minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl_minimal:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:libcurl:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl-minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl_minimal:7.76.1-40.el9_8.7:*:*:*:*:*:*:*"],"name":"libcurl-minimal","purl":"pkg:rpm/redhat/libcurl-minimal@7.76.1-40.el9_8.7?arch=x86_64&distro=rhel-9.8&upstream=curl-7.76.1-40.el9_8.7.src.rpm","type":"rpm","version":"7.76.1-40.el9_8.7","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.76.1-40.el9_8.7"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14017","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"curl","version":"7.76.1-40.el9_8.7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-14017","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14017","cwe":"CWE-567","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14017","date":"2026-10-08","epss":0.00114,"percentile":0.01374}],"risk":0.05585999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-14017","description":"A flaw was found in curl. When performing multi-threaded LDAPS (Lightweight Directory Access Protocol Secure) transfers, changes to Transport Layer Security (TLS) options in one thread could inadvertently apply globally, affecting other concurrent transfers. This could lead to unintended security posture changes, such as disabling certificate verification for other threads. This vulnerability can result in a security bypass, where expected security checks are not performed."},"relatedVulnerabilities":[{"id":"CVE-2025-14017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14017","cwe":"CWE-567","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14017","date":"2026-10-08","epss":0.00114,"percentile":0.01374}],"urls":["https://curl.se/docs/CVE-2025-14017.html","https://curl.se/docs/CVE-2025-14017.json","http://www.openwall.com/lists/oss-security/2026/01/07/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14017","description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well."}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-24515","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-24515","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24515","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-24515","date":"2026-10-08","epss":0.00189,"percentile":0.07816}],"risk":0.055755,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-24515","description":"A null pointer dereference flaw has been discovered in libexpat. The function `XML_ExternalEntityParserCreate` failed to copy the encoding handler data passed to XML_SetUnknownEncodingHandler from the parent to the new subparser. This can cause a NULL dereference from external entities that declare use of an unknown encoding. The expected impact is denial of service. It takes use of both functions `XML_ExternalEntityParserCreate` and `XML_SetUnknownEncodingHandler` for an application to be vulnerable."},"relatedVulnerabilities":[{"id":"CVE-2026-24515","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24515","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-24515","date":"2026-10-08","epss":0.00189,"percentile":0.07816}],"urls":["https://github.com/libexpat/libexpat/pull/1131","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24515","description":"In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data."}]},{"artifact":{"id":"965c5108ab84fcf4","cpes":["cpe:2.3:a:gnupg2:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*"],"name":"gnupg2","purl":"pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=rhel-9.8&upstream=gnupg2-2.3.3-5.el9_7.src.rpm","type":"rpm","version":"2.3.3-5.el9_7","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-30258","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnupg2","version":"0:2.3.3-5.el9_7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2025-30258","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"risk":0.05443500000000001,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-30258","description":"A flaw was found in GnuPG. In affected versions, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, leading to a verification denial of service."},"relatedVulnerabilities":[{"id":"CVE-2025-30258","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-30258","cwe":"CWE-754","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-30258","date":"2026-10-08","epss":0.00191,"percentile":0.07977}],"urls":["https://dev.gnupg.org/T7527","https://dev.gnupg.org/rG48978ccb4e20866472ef18436a32744350a65158","https://lists.gnupg.org/pipermail/gnupg-announce/2025q1/000491.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-30258","description":"In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a \"verification DoS.\""}]},{"artifact":{"id":"1f4db065e1dbb68d","cpes":["cpe:2.3:a:redhat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.5.0-6.el9_8.5:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.5.0-6.el9_8.5?arch=x86_64&distro=rhel-9.8&upstream=expat-2.5.0-6.el9_8.5.src.rpm","type":"rpm","version":"2.5.0-6.el9_8.5","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76957","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"expat","version":"0:2.5.0-6.el9_8.5"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-76957","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76957","date":"2026-10-08","epss":0.00107,"percentile":0.01051}],"risk":0.052965,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-76957","description":"A flaw was found in libexpat. The library's handling of custom encoding callbacks lacks proper tracking of handler call depth, which can lead to a use-after-free vulnerability. This memory corruption flaw could allow a local attacker to cause a denial of service or potentially execute arbitrary code."},"relatedVulnerabilities":[{"id":"CVE-2026-76957","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76957","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76957","date":"2026-10-08","epss":0.00107,"percentile":0.01051}],"urls":["https://github.com/libexpat/libexpat/pull/1322","https://github.com/libexpat/libexpat/pull/1329"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76957","description":"libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412."}]},{"artifact":{"id":"7df4fc0e81ada7f4","cpes":["cpe:2.3:a:policycoreutils:policycoreutils:3.6-5.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:policycoreutils:3.6-5.el9:*:*:*:*:*:*:*"],"name":"policycoreutils","purl":"pkg:rpm/redhat/policycoreutils@3.6-5.el9?arch=x86_64&distro=rhel-9.8&upstream=policycoreutils-3.6-5.el9.src.rpm","type":"rpm","version":"3.6-5.el9","language":"","licenses":["GPL-2.0-or-later"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59676","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"policycoreutils","version":"0:3.6-5.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-59676","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59676","cwe":"CWE-367","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-59676","date":"2026-10-08","epss":0.00101,"percentile":0.00839}],"risk":0.052015000000000006,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-59676","description":"A flaw was found in policycoreutils through 3.10 in seunshare. A TOCTOU race lets a local user running in an unconfined SELinux domain delete arbitrary root-owned files. Removing critical system files can cause denial of service; integrity impact is limited to unauthorized deletion."},"relatedVulnerabilities":[{"id":"CVE-2026-59676","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59676","cwe":"CWE-367","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-59676","date":"2026-10-08","epss":0.00101,"percentile":0.00839}],"urls":["https://bugzilla.suse.com/show_bug.cgi?id=1268256","https://security.opensuse.org/2026/07/15/selinux-seunshare.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59676","description":"A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files,\n\n\n\n\n\n\nThis issue affects policycoreutils through 3.10."}]},{"artifact":{"id":"7df4fc0e81ada7f4","cpes":["cpe:2.3:a:policycoreutils:policycoreutils:3.6-5.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:policycoreutils:3.6-5.el9:*:*:*:*:*:*:*"],"name":"policycoreutils","purl":"pkg:rpm/redhat/policycoreutils@3.6-5.el9?arch=x86_64&distro=rhel-9.8&upstream=policycoreutils-3.6-5.el9.src.rpm","type":"rpm","version":"3.6-5.el9","language":"","licenses":["GPL-2.0-or-later"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19079","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"policycoreutils","version":"0:3.6-5.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-19079","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19079","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19079","date":"2026-10-08","epss":0.00106,"percentile":0.01048}],"risk":0.049819999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19079","description":"A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race window between the file discovery and the label change operation by swapping directory components with symlinks, causing chcon to follow the symlink and modify SELinux labels on arbitrary system files. This could undermine SELinux mandatory access control protections on critical files such as /etc/shadow."},"relatedVulnerabilities":[{"id":"CVE-2026-19079","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19079","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-19079","date":"2026-10-08","epss":0.00106,"percentile":0.01048}],"urls":["https://access.redhat.com/errata/RHSA-2026:51861","https://access.redhat.com/security/cve/CVE-2026-19079","https://bugzilla.redhat.com/show_bug.cgi?id=2511976","https://github.com/SELinuxProject/selinux/commit/a556538c2d5d2583273e025b45c02651fef47679"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19079","description":"A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race window between the file discovery and the label change operation by swapping directory components with symlinks, causing chcon to follow the symlink and modify SELinux labels on arbitrary system files. This could undermine SELinux mandatory access control protections on critical files such as /etc/shadow."}]},{"artifact":{"id":"cfb83fcea89d51fa","cpes":["cpe:2.3:a:redhat:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.68.4-19.el9_8.10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.68.4-19.el9_8.10?arch=x86_64&distro=rhel-9.8&upstream=glib2-2.68.4-19.el9_8.10.src.rpm","type":"rpm","version":"2.68.4-19.el9_8.10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-1485","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"glib2","version":"0:2.68.4-19.el9_8.10"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-1485","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.8,"impactScore":1.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1485","cwe":"CWE-124","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1485","date":"2026-10-08","epss":0.00158,"percentile":0.04386}],"risk":0.04582,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1485","description":"A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-1485","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.8,"impactScore":1.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1485","cwe":"CWE-124","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-1485","date":"2026-10-08","epss":0.00158,"percentile":0.04386}],"urls":["https://access.redhat.com/security/cve/CVE-2026-1485","https://bugzilla.redhat.com/show_bug.cgi?id=2433325","https://gitlab.gnome.org/GNOME/glib/-/issues/3871"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1485","description":"A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability."}]},{"artifact":{"id":"965c5108ab84fcf4","cpes":["cpe:2.3:a:gnupg2:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*"],"name":"gnupg2","purl":"pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=rhel-9.8&upstream=gnupg2-2.3.3-5.el9_7.src.rpm","type":"rpm","version":"2.3.3-5.el9_7","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnupg2","version":"0:2.3.3-5.el9_7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-57062","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-57062","date":"2026-10-08","epss":0.00149,"percentile":0.03583}],"risk":0.043955,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-57062","description":"A flaw in GnuPG's gpgsm component improperly handles the Cryptographic Message Syntax (CMS) format for AES-GCM. By accepting an authentication tag length of 4 bytes instead of the required 12 bytes, this vulnerability allows for a low-impact data integrity issue where the cryptographic validity of messages could be compromised."},"relatedVulnerabilities":[{"id":"CVE-2026-57062","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-57062","date":"2026-10-08","epss":0.00149,"percentile":0.03583}],"urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182."}]},{"artifact":{"id":"965c5108ab84fcf4","cpes":["cpe:2.3:a:gnupg2:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnupg2:2.3.3-5.el9_7:*:*:*:*:*:*:*"],"name":"gnupg2","purl":"pkg:rpm/redhat/gnupg2@2.3.3-5.el9_7?arch=x86_64&distro=rhel-9.8&upstream=gnupg2-2.3.3-5.el9_7.src.rpm","type":"rpm","version":"2.3.3-5.el9_7","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnupg2","version":"0:2.3.3-5.el9_7"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.040589999999999994,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-105712","description":"A flaw was found in the gpgtar utility in GnuPG. When extracting an archive into a directory containing pre-existing symbolic links (symlinks), the tool can follow those links instead of staying within the target directory. An attacker can provide a crafted archive that, when extracted by an unsuspecting user, creates or overwrites files outside the intended destination directory. Any unauthorized file writes are limited to the filesystem permissions of the user performing the extraction."},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"81dc18ef79d2b2cb","cpes":["cpe:2.3:a:redhat:popt:1.18-8.el9:*:*:*:*:*:*:*","cpe:2.3:a:popt:popt:1.18-8.el9:*:*:*:*:*:*:*"],"name":"popt","purl":"pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=rhel-9.8&upstream=popt-1.18-8.el9.src.rpm","type":"rpm","version":"1.18-8.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18743","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"popt","version":"0:1.18-8.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18743","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18743","cwe":"CWE-131","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18743","date":"2026-10-08","epss":0.00141,"percentile":0.0296}],"risk":0.038775000000000004,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18743","description":"A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service)."},"relatedVulnerabilities":[{"id":"CVE-2026-18743","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18743","cwe":"CWE-131","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18743","date":"2026-10-08","epss":0.00141,"percentile":0.0296}],"urls":["https://access.redhat.com/errata/RHSA-2026:56984","https://access.redhat.com/security/cve/CVE-2026-18743","https://bugzilla.redhat.com/show_bug.cgi?id=2510809"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18743","description":"A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `poptConfigFileToString` function reallocates memory for buffers. Successful exploitation could result in heap metadata corruption, potentially causing the affected process to become unavailable (denial of service)."}]},{"artifact":{"id":"81dc18ef79d2b2cb","cpes":["cpe:2.3:a:redhat:popt:1.18-8.el9:*:*:*:*:*:*:*","cpe:2.3:a:popt:popt:1.18-8.el9:*:*:*:*:*:*:*"],"name":"popt","purl":"pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=rhel-9.8&upstream=popt-1.18-8.el9.src.rpm","type":"rpm","version":"1.18-8.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18739","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"popt","version":"0:1.18-8.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18739","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18739","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18739","date":"2026-10-08","epss":0.0014,"percentile":0.02913}],"risk":0.038500000000000006,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18739","description":"A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data."},"relatedVulnerabilities":[{"id":"CVE-2026-18739","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18739","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18739","date":"2026-10-08","epss":0.0014,"percentile":0.02913}],"urls":["https://access.redhat.com/errata/RHSA-2026:56984","https://access.redhat.com/security/cve/CVE-2026-18739","https://bugzilla.redhat.com/show_bug.cgi?id=2510737"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18739","description":"A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data."}]},{"artifact":{"id":"81dc18ef79d2b2cb","cpes":["cpe:2.3:a:redhat:popt:1.18-8.el9:*:*:*:*:*:*:*","cpe:2.3:a:popt:popt:1.18-8.el9:*:*:*:*:*:*:*"],"name":"popt","purl":"pkg:rpm/redhat/popt@1.18-8.el9?arch=x86_64&distro=rhel-9.8&upstream=popt-1.18-8.el9.src.rpm","type":"rpm","version":"1.18-8.el9","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18839","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"popt","version":"0:1.18-8.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-18839","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.2,"impactScore":1.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18839","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18839","date":"2026-10-08","epss":0.00114,"percentile":0.0136}],"risk":0.02964,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18839","description":"An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-18839","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.2,"impactScore":1.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18839","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18839","date":"2026-10-08","epss":0.00114,"percentile":0.0136}],"urls":["https://access.redhat.com/errata/RHSA-2026:77932","https://access.redhat.com/security/cve/CVE-2026-18839","https://bugzilla.redhat.com/show_bug.cgi?id=2511010"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18839","description":"An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application."}]},{"artifact":{"id":"5249f7f7904b9644","cpes":["cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:46.0.7:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@46.0.7","type":"python","version":"46.0.7","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/METADATA","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/RECORD","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/lib/mysqlsh/lib/python3.11/site-packages/cryptography-46.0.7.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"48.0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-537c-gmf6-5ccf","versionConstraint":">=0.5.0,<48.0.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"46.0.7"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-537c-gmf6-5ccf","fix":{"state":"fixed","versions":["48.0.1"],"available":[{"date":"2026-06-16","kind":"first-observed","version":"48.0.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-537c-gmf6-5ccf","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-537c-gmf6-5ccf","description":"Vulnerable OpenSSL included in cryptography wheels"},"relatedVulnerabilities":[]},{"artifact":{"id":"cbdfa30db142aa04","cpes":["cpe:2.3:a:gnutls:gnutls:3.8.10-9.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.8.10-9.el9_8:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.8.10-9.el9_8?arch=x86_64&distro=rhel-9.8&upstream=gnutls-3.8.10-9.el9_8.src.rpm","type":"rpm","version":"3.8.10-9.el9_8","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-88647","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnutls","version":"0:3.8.10-9.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-88647","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-88647","description":"A flaw was found in GnuTLS. This vulnerability can lead to information disclosure by allowing an attacker to bypass certificate hostname verification. A remote attacker presenting a crafted certificate can circumvent the Common Name fallback check, enabling them to eavesdrop on or intercept encrypted network communications."},"relatedVulnerabilities":[{"id":"CVE-2026-88647","cvss":[],"urls":["https://gist.github.com/lkloliver/f98ec3de1a871fdfc02b70b8b9ba7642","https://gitlab.com/gnutls/gnutls/-/issues/1802"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88647","description":"A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate."}]},{"artifact":{"id":"cbdfa30db142aa04","cpes":["cpe:2.3:a:gnutls:gnutls:3.8.10-9.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.8.10-9.el9_8:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.8.10-9.el9_8?arch=x86_64&distro=rhel-9.8&upstream=gnutls-3.8.10-9.el9_8.src.rpm","type":"rpm","version":"3.8.10-9.el9_8","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-88648","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnutls","version":"0:3.8.10-9.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-88648","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-88648","description":"A flaw was found in GnuTLS. An attacker controlling a subordinate Certificate Authority (CA) can exploit an incomplete X.509 certificate validation mechanism to bypass cross-domain Public Key Infrastructure (PKI) restrictions. This allows unauthorized certificates to be accepted as valid, potentially enabling the attacker to impersonate trusted domains and intercept secure communications."},"relatedVulnerabilities":[{"id":"CVE-2026-88648","cvss":[],"urls":["https://gist.github.com/lkloliver/1f2a97cb8d0b31aa27b6bd0354358d7d","https://www.rfc-editor.org/rfc/rfc5280#section-4.2.1.10","https://www.rfc-editor.org/rfc/rfc5280#section-6.1.4"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88648","description":"Incomplete X.509 implementation in GnuTLS v3.8.13 allows attackers controlling a subordinate Certificate Authority to bypass cross-domain PKI restrictions and issue unauthorized certificates."}]},{"artifact":{"id":"aff0baca8a045287","cpes":["cpe:2.3:a:libblkid:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libblkid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libblkid","purl":"pkg:rpm/redhat/libblkid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53613","description":"When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root."},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"9ee075f0f02757cc","cpes":["cpe:2.3:a:libfdisk:libfdisk:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libfdisk:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libfdisk","purl":"pkg:rpm/redhat/libfdisk@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53613","description":"When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root."},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"66ba386a85828620","cpes":["cpe:2.3:a:libmount:libmount:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libmount:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libmount","purl":"pkg:rpm/redhat/libmount@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53613","description":"When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root."},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"0a9bd32f064c052f","cpes":["cpe:2.3:a:libsmartcols:libsmartcols:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libsmartcols:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libsmartcols","purl":"pkg:rpm/redhat/libsmartcols@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53613","description":"When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root."},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"63e8f89642ab1486","cpes":["cpe:2.3:a:libuuid:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libuuid:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"libuuid","purl":"pkg:rpm/redhat/libuuid@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53613","description":"When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root."},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"28dc83c2657e893e","cpes":["cpe:2.3:a:util-linux:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:rpm/redhat/util-linux@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["GPLv2 and GPLv2+ and LGPLv2+ and BSD with advertising and Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"0:2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53613","description":"When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root."},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"97ebf56955dbe4a2","cpes":["cpe:2.3:a:util-linux-core:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux-core:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_core:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux_core:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux-core:2.37.4-25.el9:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux_core:2.37.4-25.el9:*:*:*:*:*:*:*"],"name":"util-linux-core","purl":"pkg:rpm/redhat/util-linux-core@2.37.4-25.el9?arch=x86_64&distro=rhel-9.8&upstream=util-linux-2.37.4-25.el9.src.rpm","type":"rpm","version":"2.37.4-25.el9","language":"","licenses":["GPLv2 and GPLv2+ and LGPLv2+ and BSD with advertising and Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"util-linux","version":"2.37.4-25.el9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"util-linux","version":"2.37.4-25.el9"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-53613","description":"When an /etc/fstab entry is configured with the user or users option, mount(8) validates the target path before performing the mount syscall, creating a Time-of-Check-Time-of-Use (TOCTOU) window. A local unprivileged user with write access to an ancestor directory of the mount target can swap that directory to redirect the mount to an arbitrary root-owned location, potentially escalating privileges to root."},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"cbdfa30db142aa04","cpes":["cpe:2.3:a:gnutls:gnutls:3.8.10-9.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.8.10-9.el9_8:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.8.10-9.el9_8?arch=x86_64&distro=rhel-9.8&upstream=gnutls-3.8.10-9.el9_8.src.rpm","type":"rpm","version":"3.8.10-9.el9_8","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-67693","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"gnutls","version":"0:3.8.10-9.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-67693","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-67693","description":"A flaw was found in GnuTLS. The certificate verification process fails to properly reject end-entity digital certificates containing contradictory Key Usage (KU) and Extended Key Usage (EKU) extensions, which define the permitted cryptographic operations of a certificate. A remote attacker could exploit this flaw by presenting a specially crafted certificate to bypass validation controls, potentially resulting in information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-67693","cvss":[],"urls":["http://gnutls.com","https://gist.github.com/lkloliver/6fbfc191bc6163942c8017551ac3f238","https://gitlab.com/gnutls/gnutls/-/blob/3.8.13/lib/x509/verify.c#L1119-1178"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67693","description":"An issue in gnutls v.3.8.13 allows an attacker to obtain sensitive information via failing to reject end-entity X.509 certificates that contain a contradictory combination of Key Usage (KU) and Extended Key Usage (EKU)"}]},{"artifact":{"id":"7e23f8149f581507","cpes":["cpe:2.3:a:krb5-libs:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5-libs:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5_libs:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5_libs:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*"],"name":"krb5-libs","purl":"pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=rhel-9.8&upstream=krb5-1.21.1-10.el9_8.src.rpm","type":"rpm","version":"1.21.1-10.el9_8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5","version":"1.21.1-10.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107708","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"krb5","version":"1.21.1-10.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-107708","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107708","cwe":"CWE-476","type":"Primary","source":"disclosure@vulncheck.com"}],"risk":0,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-107708","description":"A flaw was found in krb5. This vulnerability allows a compromised or malicious cross-realm trusted Key Distribution Center (KDC) to cause a Denial of Service (DoS). By sending an S4U2Proxy delegation request containing a malformed client name within a Privilege Attribute Certificate (PAC), an attacker can trigger a NULL pointer dereference that crashes the KDC daemon, interrupting authentication services."},"relatedVulnerabilities":[{"id":"CVE-2026-107708","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.9,"impactScore":3.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107708","cwe":"CWE-476","type":"Primary","source":"disclosure@vulncheck.com"}],"urls":["https://github.com/krb5/krb5","https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/kdc/kdc_util.c#L639-L676","https://github.com/krb5/krb5/commit/a88a18cafa1040a0c4f9c8d08288fc98831ec86d","https://github.com/krb5/krb5/commit/f6e2c397ceda6467ebbaab8ed66d4895c9f1d6a7","https://github.com/krb5/krb5/pull/1510","https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-kdc-null-pointer-dereference-via-s4u2proxy-pac"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107708","description":"MIT krb5 through 1.22.2 contains a NULL pointer dereference vulnerability in the KDC's get_pac_princ_with_realm() that returns success while leaving the client principal NULL on malformed names. A malicious or compromised cross-realm trusted KDC can send an S4U2Proxy request with a PAC carrying a malformed client name to crash krb5kdc and deny authentication."}]},{"artifact":{"id":"7e23f8149f581507","cpes":["cpe:2.3:a:krb5-libs:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5-libs:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5_libs:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5_libs:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-libs:1.21.1-10.el9_8:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_libs:1.21.1-10.el9_8:*:*:*:*:*:*:*"],"name":"krb5-libs","purl":"pkg:rpm/redhat/krb5-libs@1.21.1-10.el9_8?arch=x86_64&distro=rhel-9.8&upstream=krb5-1.21.1-10.el9_8.src.rpm","type":"rpm","version":"1.21.1-10.el9_8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/rpmdb.sqlite","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/var/lib/rpm/rpmdb.sqlite","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5","version":"1.21.1-10.el9_8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-107778","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"9.8"},"package":{"name":"krb5","version":"1.21.1-10.el9_8"},"namespace":"redhat:distro:redhat:9"}}],"vulnerability":{"id":"CVE-2026-107778","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107778","cwe":"CWE-476","type":"Primary","source":"disclosure@vulncheck.com"}],"risk":0,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:9","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-107778","description":"A flaw was found in krb5. An authenticated remote attacker can cause a Denial of Service (DoS) by sending specially crafted forwarded credentials containing mismatched credential entries. This improper handling triggers a null pointer dereference, causing the service to crash and become unavailable."},"relatedVulnerabilities":[{"id":"CVE-2026-107778","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107778","cwe":"CWE-476","type":"Primary","source":"disclosure@vulncheck.com"}],"urls":["https://github.com/krb5/krb5","https://github.com/krb5/krb5/blob/krb5-1.22.2-final/src/lib/krb5/krb/rd_cred.c#L77-L112","https://github.com/krb5/krb5/commit/48afa9abb89ab2176bb20624d87d010b9984fc08","https://github.com/krb5/krb5/commit/62196e2b269159a5465f5b8d0ed7cf6f29c3282a","https://github.com/krb5/krb5/pull/1511","https://www.vulncheck.com/advisories/mit-krb5-through-1.22.2-null-pointer-dereference-via-krb5-rd-cred"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107778","description":"MIT Kerberos 5 (krb5) through 1.22.2 contains a NULL pointer dereference in make_cred_list() in rd_cred.c that allows authenticated Kerberos clients to crash services by sending mismatched KRB-CRED arrays. Attackers can send forwarded credentials with more tickets than ticket_info entries through gss_accept_sec_context() to crash GSS-API acceptor services, causing denial of service."}]},{"artifact":{"id":"6e4431f0ac788048","cpes":["cpe:2.3:a:golang:networking:v0.58.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.58.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.58.0","type":"go-module","version":"v0.58.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=","mainModule":"github.com/percona/telemetry-agent","architecture":"amd64","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.58.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"6e4431f0ac788048","cpes":["cpe:2.3:a:golang:networking:v0.58.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.58.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.58.0","type":"go-module","version":"v0.58.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=","mainModule":"github.com/percona/telemetry-agent","architecture":"amd64","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.58.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"6e4431f0ac788048","cpes":["cpe:2.3:a:golang:networking:v0.58.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.58.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.58.0","type":"go-module","version":"v0.58.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=","mainModule":"github.com/percona/telemetry-agent","architecture":"amd64","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.58.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"6e4431f0ac788048","cpes":["cpe:2.3:a:golang:networking:v0.58.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.58.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.58.0","type":"go-module","version":"v0.58.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=","mainModule":"github.com/percona/telemetry-agent","architecture":"amd64","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.58.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"6e4431f0ac788048","cpes":["cpe:2.3:a:golang:networking:v0.58.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.58.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.58.0","type":"go-module","version":"v0.58.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=","mainModule":"github.com/percona/telemetry-agent","architecture":"amd64","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.58.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"cf595d274b042f8e","cpes":["cpe:2.3:a:golang:go:1.27.1:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.27.1","type":"go-module","version":"go1.27.1","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.27.1"},"locations":[{"path":"/usr/bin/percona-telemetry-agent","layerID":"sha256:a92890b75dbcb87c370ae3a720a1d8f666da53c1079df1e59e603be382954471","accessPath":"/usr/bin/percona-telemetry-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.27.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":">=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.27.1"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T23:32:34.888Z","grype_db_version":"2026-10-09T06:32:32.000Z"}